Type:
Bug
Priority:
Blocker
Resolution:
Fixed
Affects Version/s:
10.5
Simply based on what I see I report this as bug since MariaDB Audit masks the password from CREATE USER but fails to recognize different forms of the same command.
20241128 15:58:36,fedora,root,localhost,150,276260,QUERY,,'CREATE USER \'claudio\'@\'%\' IDENTIFIED BY *****',1396
20241128 15:56:42,fedora,root,localhost,149,276256,QUERY,,'CREATE OR REPLACE USER \'monty\'@\'%\' IDENTIFIED BY \'123\'',0
20241128 15:56:54,fedora,root,localhost,149,276257,QUERY,,'SET STATEMENT max_statement_time=10.000000 FOR CREATE USER \'sergio\'@\'%\' IDENTIFIED BY \'123\'',0
https://jira.mariadb.org/browse/MDEV-7134
So if it was decided to mask the password for the CREATE USER command imho it should be done so to detect the different forms of the same command.
I did not test for other types of DCLs.
causes
MDEV-35604
SIGSEGV in filter_query_type | log_statement_ex / auditing
Closed
{"report":{"fcp":1245.9000000059605,"ttfb":194.80000001192093,"pageVisibility":"visible","entityId":131822,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"8ccb8bbc-f8ee-41e2-99d6-4fd3a0202e39","navigationType":0,"readyForUser":1321.800000011921,"redirectCount":0,"resourceLoadedEnd":1956.6000000089407,"resourceLoadedStart":200.30000001192093,"resourceTiming":[{"duration":571,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bv2/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":200.30000001192093,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":200.30000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":771.3000000119209,"responseStart":0,"secureConnectionStart":0},{"duration":570.9000000059605,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bv2/820016/12ta74/2380add21a9a1006587582385952de73/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":200.70000000298023,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":200.70000000298023,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":771.6000000089407,"responseStart":0,"secureConnectionStart":0},{"duration":573.7999999970198,"initiatorType":"script","name":"https://jira.mariadb.org/s/e9b27a47da5fb0f74a35acd57e9847fb-CDN/lu2bv2/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":200.90000000596046,"connectEnd":200.90000000596046,"connectStart":200.90000000596046,"domainLookupEnd":200.90000000596046,"domainLookupStart":200.90000000596046,"fetchStart":200.90000000596046,"redirectEnd":0,"redirectStart":0,"requestStart":200.90000000596046,"responseEnd":774.7000000029802,"responseStart":774.7000000029802,"secureConnectionStart":200.90000000596046},{"duration":638.2000000029802,"initiatorType":"script","name":"https://jira.mariadb.org/s/c32eb0da7ad9831253f8397e6cc26afd-CDN/lu2bv2/820016/12ta74/2380add21a9a1006587582385952de73/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":201,"connectEnd":201,"connectStart":201,"domainLookupEnd":201,"domainLookupStart":201,"fetchStart":201,"redirectEnd":0,"redirectStart":0,"requestStart":201,"responseEnd":839.2000000029802,"responseStart":839.2000000029802,"secureConnectionStart":201},{"duration":641.7999999970198,"initiatorType":"script","name":"https://jira.mariadb.org/s/bc0bcb146314416123c992714ee00ff7-CDN/lu2bv2/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":201.30000001192093,"connectEnd":201.30000001192093,"connectStart":201.30000001192093,"domainLookupEnd":201.30000001192093,"domainLookupStart":201.30000001192093,"fetchStart":201.30000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":201.30000001192093,"responseEnd":843.1000000089407,"responseStart":843.1000000089407,"secureConnectionStart":201.30000001192093},{"duration":642,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":201.5,"connectEnd":201.5,"connectStart":201.5,"domainLookupEnd":201.5,"domainLookupStart":201.5,"fetchStart":201.5,"redirectEnd":0,"redirectStart":0,"requestStart":201.5,"responseEnd":843.5,"responseStart":843.5,"secureConnectionStart":201.5},{"duration":642.2000000029802,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":201.6000000089407,"connectEnd":201.6000000089407,"connectStart":201.6000000089407,"domainLookupEnd":201.6000000089407,"domainLookupStart":201.6000000089407,"fetchStart":201.6000000089407,"redirectEnd":0,"redirectStart":0,"requestStart":201.6000000089407,"responseEnd":843.8000000119209,"responseStart":843.8000000119209,"secureConnectionStart":201.6000000089407},{"duration":718.2999999970198,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bv2/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":201.80000001192093,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":201.80000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":920.1000000089407,"responseStart":0,"secureConnectionStart":0},{"duration":642.2000000029802,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":202.1000000089407,"connectEnd":202.1000000089407,"connectStart":202.1000000089407,"domainLookupEnd":202.1000000089407,"domainLookupStart":202.1000000089407,"fetchStart":202.1000000089407,"redirectEnd":0,"redirectStart":0,"requestStart":202.1000000089407,"responseEnd":844.3000000119209,"responseStart":844.3000000119209,"secureConnectionStart":202.1000000089407},{"duration":718.2000000029802,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bv2/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":202.20000000298023,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":202.20000000298023,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":920.4000000059605,"responseStart":0,"secureConnectionStart":0},{"duration":642.7999999970198,"initiatorType":"script","name":"https://jira.mariadb.org/s/719848dd97ebe0663199f49a3936487a-CDN/lu2bv2/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":202.30000001192093,"connectEnd":202.30000001192093,"connectStart":202.30000001192093,"domainLookupEnd":202.30000001192093,"domainLookupStart":202.30000001192093,"fetchStart":202.30000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":202.30000001192093,"responseEnd":845.1000000089407,"responseStart":845.1000000089407,"secureConnectionStart":202.30000001192093},{"duration":1179.699999988079,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":203.30000001192093,"connectEnd":203.30000001192093,"connectStart":203.30000001192093,"domainLookupEnd":203.30000001192093,"domainLookupStart":203.30000001192093,"fetchStart":203.30000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":203.30000001192093,"responseEnd":1383,"responseStart":1383,"secureConnectionStart":203.30000001192093},{"duration":1753.2999999970198,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bv2/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":203.30000001192093,"connectEnd":203.30000001192093,"connectStart":203.30000001192093,"domainLookupEnd":203.30000001192093,"domainLookupStart":203.30000001192093,"fetchStart":203.30000001192093,"redirectEnd":0,"redirectStart":0,"requestStart":203.30000001192093,"responseEnd":1956.6000000089407,"responseStart":1956.6000000089407,"secureConnectionStart":203.30000001192093},{"duration":471,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":931.9000000059605,"connectEnd":931.9000000059605,"connectStart":931.9000000059605,"domainLookupEnd":931.9000000059605,"domainLookupStart":931.9000000059605,"fetchStart":931.9000000059605,"redirectEnd":0,"redirectStart":0,"requestStart":931.9000000059605,"responseEnd":1402.9000000059605,"responseStart":1402.800000011921,"secureConnectionStart":931.9000000059605},{"duration":749.2999999970198,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":1238.800000011921,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":1238.800000011921,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1988.1000000089407,"responseStart":0,"secureConnectionStart":0}],"fetchStart":1,"domainLookupStart":1,"domainLookupEnd":1,"connectStart":1,"connectEnd":1,"requestStart":42,"responseStart":195,"responseEnd":196,"domLoading":198,"domInteractive":1992,"domContentLoadedEventStart":1992,"domContentLoadedEventEnd":2033,"domComplete":3244,"loadEventStart":3244,"loadEventEnd":3246,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1958.4000000059605},{"name":"bigPipe.sidebar-id.end","time":1959.300000011921},{"name":"bigPipe.activity-panel-pipe-id.start","time":1959.5},{"name":"bigPipe.activity-panel-pipe-id.end","time":1962},{"name":"activityTabFullyLoaded","time":2039.1000000089407}],"measures":[],"correlationId":"d94b24e85b4a36","effectiveType":"4g","downlink":9.5,"rtt":0,"serverDuration":97,"dbReadsTimeInMs":13,"dbConnsTimeInMs":22,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}