Clickhouse Cloud vulnerabilities

4 known vulnerabilities affecting clickhouse/clickhouse_cloud.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-22412MEDIUMCVSS 4.9fixed in 24.0.2.545352024-03-18
CVE-2024-22412 [MEDIUM] CWE-863 CVE-2024-22412: ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud C ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering prior to version 24.0.2.54535 and in github.com/clickhouse/clickhouse version 23.1. Query caching bypasses the role based access controls and the policies being enforced on roles. In affected versions, the query cache only respects
nvd
CVE-2023-48704HIGHCVSS 7.5fixed in 23.9.2.475512023-12-22
CVE-2023-48704 [HIGH] CWE-120 CVE-2023-48704: ClickHouse is an open-source column-oriented database management system that allows generating analy ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface exposed by default on port 9000/tcp, triggering a bug in the decompression logi
nvd
CVE-2023-48298HIGHCVSS 7.5≥ 23.9, ≤ 23.9.2.474752023-12-21
CVE-2023-48298 [HIGH] CVE-2023-48298: ClickHouse® is an open-source column-oriented database management system that allows generating anal ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered and exploited by an unauthenticated attacker. The vulnerability is very similar to CV
nvd
CVE-2023-47118CRITICALCVSS 9.8fixed in 23.9.2.474752023-12-20
CVE-2023-47118 [CRITICAL] CWE-122 CVE-2023-47118: ClickHouse® is an open-source column-oriented database management system that allows generating anal ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface exposed by default on port 9000/tcp, triggering a bug in the decompression
nvd