Skip to content

security(pipes): a quoted placeholder lets a value break out of its literal #662

Description

@EricAndrechek

Area: pipes · security

Expected: a pipe parameter's value cannot change the structure of the statement, whatever the template looks like.

Actual: formatParamValue (internal/pipes/pipes.go) renders a string value as its own quoted literal ('…', with \ and ' escaped). If the template also puts quotes around the placeholder, e.g. WHERE id = '{{id}}', the value's opening quote closes the author's. The value OR 1=1 OR id = binds to:

WHERE id = '' OR 1=1 OR id = ''

The bind output is verified against BindParams. That ClickHouse then matches every row is inferred.

Impact:

  • In a read pipe, this defeats the template's filter.
  • In a write pipe, e.g. ALTER TABLE t DELETE WHERE id = '{{id}}', it deletes every row.
  • A pipe is authorized only by its allowed_roles, so any role the operator allowed can do this, including default_role.

Mitigation until this is fixed: write each placeholder bare (WHERE id = {{id}}). #634 adds this rule to pipes.mdx.

Scope: make BindParams, or the check that runs when a pipe is loaded or put, refuse a template whose placeholder sits inside a quoted literal, after stripping comments. The mistake then fails when the pipe is defined, instead of binding silently.

Related:

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/pipesNamed query pipesbugSomething isn't workingsecuritySecurity-sensitive issue or fix

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions