[bug](http) MetaInfoAction.getAllDatabases() leaks unfiltered db list, bypassing SHOW privilege
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 76/100
Direzione di ricerca
Inizia da fe/fe-core/src/main/java/org/apache/doris/httpv2/rest/MetaInfoAction.java, in getAllDatabases(), quindi confronta il flusso di filtraggio e paginazione in fe/fe-core/src/main/java/org/apache/doris/httpv2/restv2/MetaInfoActionV2.java. Il lavoro è completato quando l'endpoint v1 ordina e restituisce solo i nomi dei database consentiti da SHOW, senza usare l'elenco non filtrato nella risposta.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
MetaInfoAction.getAllDatabases() (the v1 HTTP metadata interface) returns the full list of database names regardless of the caller's SHOW privilege. The privilege-filtered result (dbNameSet) is computed but never used; the method sorts and returns the unfiltered dbNames.
This is distinct from PR #65126 — it is a pre-existing master bug, not introduced by that PR. The only change PR #65126 made to this method was the line:
- List<String> dbNames = catalog.getDbNames();
+ List<String> dbNames = new ArrayList<>(catalog.getDbNames());
which was needed to fix an UnsupportedOperationException after getDbNames() started returning an immutable list. It is unrelated to the privilege-filtering bug.
Affected code
fe/fe-core/src/main/java/org/apache/doris/httpv2/rest/MetaInfoAction.java
List<String> dbNames = new ArrayList<>(catalog.getDbNames()); // L108 all db names
List<String> dbNameSet = Lists.newArrayList(); // L109
for (String db : dbNames) {
if (!Env.getCurrentEnv().getAccessManager()
.checkDbPriv(ConnectContext.get(), InternalCatalog.INTERNAL_CATALOG_NAME, db,
PrivPredicate.SHOW)) {
continue; // skip db without SHOW
}
dbNameSet.add(db); // L116 filtered result
}
Collections.sort(dbNames); // L119 sorts dbNames (unfiltered)
Pair<Integer, Integer> fromToIndex = getFromToIndex(request, dbNames.size());
return ResponseEntityBuilder.ok(dbNames.subList(...)); // L123 returns UNFILTERED dbNames
dbNameSet is dead code; the response returns the unfiltered, all-privilege dbNames.
Auth surface / impact
checkWithCookiealways requires a valid authenticated session (Authorization header or valid cookie), so this is not anonymous access.enable_all_http_authdefaults tofalsein most deployments. With the default, any authenticated non-admin user hitting/api/meta/{ns}/databasescan enumerate every database name in the catalog, bypassingSHOWprivilege.- When
enable_all_http_auth = true, only admin can reach the endpoint, so the leakage is limited to admins.
Impact: information disclosure / privilege bypass at the metadata-enumeration level (database names only; table/column data is gated by other checks).
Correct reference (v2)
MetaInfoActionV2.getAllDatabases() does this correctly — it accumulates into filteredDbNames, sorts it, and returns it:
fe/fe-core/src/main/java/org/apache/doris/httpv2/restv2/MetaInfoActionV2.java (lines ~130–145)
List<String> filteredDbNames = Lists.newArrayList();
// ... checkDbPriv(SHOW) -> filteredDbNames.add(db)
Collections.sort(filteredDbNames);
return ResponseEntityBuilder.ok(filteredDbNames.subList(...));
Suggested fix
Align v1 with v2: return the privilege-filtered (and sorted) dbNameSet / filteredDbNames instead of dbNames, and drop the dead code. This is outside the scope of PR #65126 (external metadata cache refactor) and is tracked separately here.
Related
- PR #65126 (
[refactor](meta cache) Refactor external metadata cache with MetaCacheEntry)
- Lingua principale
- Java
- Stelle
- 16k
- Fork
- 4k
- Merge medio
- 1g 23h
- PR unite (30g)
- 623
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di apache/doris
-
4.1.4.1 Release NoteApertarelease notes
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno
-
[Bug] FE metric http_copy_into_query_err_total is registered under the upload error nameForse già presa @manesioz l’ha presa 10 giorni fa. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
apache/doris#68505 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
[Pipeline issue] build pipeline does not support to trigger check_coverage_fe by commentForse già presa @Asthenia0412 l’ha presa 21 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
apache/doris#67785 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[Bug][dbt-doris] Large SQL statements are silently corrupted by mysql-connector-python's C extension — force use_pure=TrueForse già presa @bringyou l’ha presa 29 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
apache/doris#67546 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di apache/doris
Issue simili
-
CalendarEventAttendance/get returns eventAttendanceStatus while the doc says attendanceStatusForse già presa @chibenwa l’ha presa oggi. Apertabug claude
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
linagora/tmail-backend#2697 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
apache/skywalking#14120 ·
I maintainer di solito rispondono entro 1 giorno
-
[BUG] Case-insensitive search suggestions miss items when the JVM default locale is TurkishForse già presa @thswlsqls l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
[Feature] 关于启动游戏进度条显示的优化Apertaenhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
HMCL-dev/HMCL#6943 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
NameAllocator generates colliding identifiers with ignorable charactersForse già presa @PHJ2000 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
I maintainer di solito rispondono entro 1 giorno