[bug](http) MetaInfoAction.getAllDatabases() leaks unfiltered db list, bypassing SHOW privilege
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 76/100
Research direction
Start in fe/fe-core/src/main/java/org/apache/doris/httpv2/rest/MetaInfoAction.java at getAllDatabases(), then compare the filtering and pagination flow in fe/fe-core/src/main/java/org/apache/doris/httpv2/restv2/MetaInfoActionV2.java. Done means the v1 endpoint sorts and returns only database names permitted by SHOW, without using the unfiltered list in its response.
Written by the indexing model from the issue text.
Description
Summary
MetaInfoAction.getAllDatabases() (the v1 HTTP metadata interface) returns the full list of database names regardless of the caller's SHOW privilege. The privilege-filtered result (dbNameSet) is computed but never used; the method sorts and returns the unfiltered dbNames.
This is distinct from PR #65126 — it is a pre-existing master bug, not introduced by that PR. The only change PR #65126 made to this method was the line:
- List<String> dbNames = catalog.getDbNames();
+ List<String> dbNames = new ArrayList<>(catalog.getDbNames());
which was needed to fix an UnsupportedOperationException after getDbNames() started returning an immutable list. It is unrelated to the privilege-filtering bug.
Affected code
fe/fe-core/src/main/java/org/apache/doris/httpv2/rest/MetaInfoAction.java
List<String> dbNames = new ArrayList<>(catalog.getDbNames()); // L108 all db names
List<String> dbNameSet = Lists.newArrayList(); // L109
for (String db : dbNames) {
if (!Env.getCurrentEnv().getAccessManager()
.checkDbPriv(ConnectContext.get(), InternalCatalog.INTERNAL_CATALOG_NAME, db,
PrivPredicate.SHOW)) {
continue; // skip db without SHOW
}
dbNameSet.add(db); // L116 filtered result
}
Collections.sort(dbNames); // L119 sorts dbNames (unfiltered)
Pair<Integer, Integer> fromToIndex = getFromToIndex(request, dbNames.size());
return ResponseEntityBuilder.ok(dbNames.subList(...)); // L123 returns UNFILTERED dbNames
dbNameSet is dead code; the response returns the unfiltered, all-privilege dbNames.
Auth surface / impact
checkWithCookiealways requires a valid authenticated session (Authorization header or valid cookie), so this is not anonymous access.enable_all_http_authdefaults tofalsein most deployments. With the default, any authenticated non-admin user hitting/api/meta/{ns}/databasescan enumerate every database name in the catalog, bypassingSHOWprivilege.- When
enable_all_http_auth = true, only admin can reach the endpoint, so the leakage is limited to admins.
Impact: information disclosure / privilege bypass at the metadata-enumeration level (database names only; table/column data is gated by other checks).
Correct reference (v2)
MetaInfoActionV2.getAllDatabases() does this correctly — it accumulates into filteredDbNames, sorts it, and returns it:
fe/fe-core/src/main/java/org/apache/doris/httpv2/restv2/MetaInfoActionV2.java (lines ~130–145)
List<String> filteredDbNames = Lists.newArrayList();
// ... checkDbPriv(SHOW) -> filteredDbNames.add(db)
Collections.sort(filteredDbNames);
return ResponseEntityBuilder.ok(filteredDbNames.subList(...));
Suggested fix
Align v1 with v2: return the privilege-filtered (and sorted) dbNameSet / filteredDbNames instead of dbNames, and drop the dead code. This is outside the scope of PR #65126 (external metadata cache refactor) and is tracked separately here.
Related
- PR #65126 (
[refactor](meta cache) Refactor external metadata cache with MetaCacheEntry)
- Dominant language
- Java
- Stars
- 16k
- Forks
- 4k
- Avg merge
- 2d 1m
- Merged PRs (30d)
- 637
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from apache/doris
-
4.1.4.1 Release NoteOpenrelease notes
Difficulty 1/5 Under an hour Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
apache/doris#68505 · 2 comments ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
apache/doris#67785 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
apache/doris#67546 · 1 comment ·
Maintainers usually reply within 1 day
Similar issues
-
type: possible bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
grimmory-tools/grimmory#2850 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
aoqia194/leaf-loader#19 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
apache/streampark#4521 ·