CVE-2019-18657Injection in Clickhouse

CWE-74Injection2 documents2 sources
Severity
5.3MEDIUMNVD
EPSS
0.5%
top 33.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 31
Latest updateMay 24

Description

ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDclickhouse/clickhouse< 19.13.5.44

Patches

🔴Vulnerability Details

1
GHSA
GHSA-qgx5-5m84-4526: ClickHouse before 192022-05-24