Skip to content

v1.5.1

Choose a tag to compare

@github-actions github-actions released this 25 Sep 21:23
· 57 commits to main since this release

What's new in 1.5.1

A security release. A review of the whole app found a number of ways a file, a web page or another program on the computer could get the app to do more than it should. All of them are fixed. Please update.

Action needed for PAM / LDAP accounts. An account that signs in with its password as typed (MariaDB auth_pam, MySQL Enterprise PAM or LDAP) no longer sends it over SSL required or default on its own: those modes do not check the server's certificate, so someone in between could pose as the server and read the password. Use verify-ca or verify, or - on a network you trust - tick the new PAM / LDAP sign-in box in the saved connection.

Import

  • A dump file could run commands on your computer. MySQL's command-line client carries out system <command> and tee <file> found in a file it loads; a dump someone sends you could hold them. Import now runs the client in binary mode, where it refuses every client command. Raw NUL bytes go through as well, so the "Binary mode" box is gone - it is always on.
  • A database or table name that starts with - could be read by the client tools as an option. Names are now passed so that they are always names.

Read-only / safe mode

  • Several statements that write got through: EXPLAIN ANALYZE of a multi-table UPDATE or DELETE (MySQL runs it), SET GLOBAL or PERSIST after another assignment, SET RESOURCE GROUP, INTO OUTFILE after an earlier INTO @var, and names or strings with backslashes read the wrong way. All are refused now.
  • A connection saved as read-only stays read-only in the app's backend, whatever the page asks - unless another saved connection to the same account is not read-only.

The app itself

  • The window runs under a content security policy: it loads and sends nothing anywhere but the app.
  • Files are written only where you picked them in a Save dialog.
  • Settings saves only its own settings, each checked; a client tool has to be mysql or mysqldump, an .exe, on this computer.
  • Temporary files that hold a password are private to you, removed after use, and cleaned up at the next start if the app was killed. The SSH password no longer stays in ssh's environment for as long as the tunnel runs.
  • The command-line tools refuse LOAD DATA LOCAL, so a server cannot ask them for a file.
  • A password in SQL that the app logs, shows in a message or keeps with your open tabs is written as '***'.
  • WAMP and XAMPP folders are no longer searched for client tools: any user of the computer can write to them. Pick their tools in Settings.
  • A server error mentioning "ssl" is no longer taken for a TLS failure and retried unencrypted.
  • A saved transaction's Apply writes values for that session's own sql_mode.
  • Table and column names with quotes, line breaks or names like constructor no longer break Compare, the ERD, Export or Import.

The README has a new Security notes section on what read-only, import, SSL and SSH tunnels do and do not protect against.

Verify your download

These installers are not code-signed. Compare what you downloaded against the SHA-256 below:

f5109be54f0db1ae170bf1af41a000c40179cf78ce8a2d28b9970747f299c69d  NOBS.SQL.Editor_1.5.1_x64-setup.exe
2af1f19c89d261e3952bf0701b208f91aea6a5ee0c0f12f3d62e113b84901b0d  NOBS.SQL.Editor_1.5.1_x64_en-US.msi

PowerShell: Get-FileHash .\<file> -Algorithm SHA256

See CODE_SIGNING.md for what this does and does not prove.

Full Changelog: v1.5.0...v1.5.1