Researchers discovered vulnerabilities in Google Cloud SQL that allowed gaining unauthorized shell access to MySQL instances. By chaining SQL injection, parameter injection in mysqldump, and network spoofing, they were able to escape a Docker container and gain full access to the host VM running Cloud SQL.
Affected Services
Cloud SQL
Remediation
None required. Google patched the vulnerabilities.
Monitor for suspicious export operations and network activity on Cloud SQL instances. Review logs for anomalous mysqldump commands or container escapes.