Bug #79011 [Opn]: MySQL caching_sha2_password Access denied for password with more than 20 chars
| From: | requinix@php.net | Date: | Mon, 23 Dec 2019 02:23:35 +0000 |
| Subject: | Bug #79011 [Opn]: MySQL caching_sha2_password Access denied for password with more than 20 chars | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224486@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79011&edit=1
ID: 79011
Updated by: requinix@php.net
Reported by: bendix dot ohlhauser at gmail dot com
Summary: MySQL caching_sha2_password Access denied for
password with more than 20 chars
Status: Open
Type: Bug
Package: MySQLi related
Operating System: Ubuntu 18 LTS
PHP Version: 7.4.1
Block user comment: N
Private report: N
New Comment:
It's *potentially* a security issue because the authentication system (<- important)
doesn't seem to be working correctly. Don't know exactly how it's malfunctioning,
which means don't know exactly what is wrong or whether it can be abused.
Previous Comments:
------------------------------------------------------------------------
[2019-12-23 02:16:58] bugreports at gmail dot com
> --- Potential security issue, not sure though ---
how could "Access denied" be a security issue to begin with?
if you get access with a random wrong password it would be
------------------------------------------------------------------------
[2019-12-23 02:07:02] bendix dot ohlhauser at gmail dot com
It actually happens with passwords with over 19 charaters. See my stackoverflow answer.
It is probably a issue with mysql, but since I'm not 100% sure, I'll leave this open.
Probably not a security issue.
------------------------------------------------------------------------
[2019-12-21 20:26:08] requinix@php.net
PHP isn't somehow running your script differently because it knows you did something with the
mysql client, so this sounds like an issue with MySQL's authentication system.
We can wait to see what they think about it.
https://bugs.mysql.com/bug.php?id=98048
------------------------------------------------------------------------
[2019-12-21 19:15:48] bendix dot ohlhauser at gmail dot com
Image showing the issue: https://imgur.com/a/AomDhtt
------------------------------------------------------------------------
[2019-12-21 03:06:48] bendix dot ohlhauser at gmail dot com
Description:
------------
--- Potential security issue, not sure though ---
--- Potentially issue with MySQL, instead of PHP, not sure though ---
Disclaimer: This might look like user error, but most certainly is not.
See: https://stackoverflow.com/questions/59432704/php-7-4-mysql-caching-sha2-password-randomly-denying-passwords
MySQL caching_sha2_password is supported by PHP7.4, but it handles the passwords incorrectly.
The following password via PHP: l0QDEptp*L6tNo28ey^8
Results in Access Denied.
Logging in to the account via mysql shell and running it again fixed the issue.
Also, removing a character fixed the issue.
Regarding php.ini: opcache is enabled.
Feel free to contact me for additional information.
Test script:
---------------
const DB_CHARSET = 'UTF8MB4';
const DB_HOST = '127.0.0.1';
const DB_USERNAME = 'test';
const DB_PASSWORD = '';
$mysqli = new mysqli(DB_HOST, DB_USERNAME, DB_PASSWORD, DB_NAME);
Expected result:
----------------
Successful login
Actual result:
--------------
PHP Warning: mysqli::__construct(): (HY000/1045): Access denied for user
'test'@'localhost' (using password: YES) in /db.php on line 5
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79011&edit=1