Lucene search

K
cve[email protected]CVE-2022-44011
HistoryNov 23, 2023 - 4:15 p.m.

CVE-2022-44011

2023-11-2316:15:07
CWE-787
web.nvd.nist.gov
8
clickhouse
authenticated user
heap buffer overflow
capnproto
nvd
cve-2022-44011

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.5%

An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

Affected configurations

NVD
Node
clickhouseclickhouseRange<22.3.12.19
OR
clickhouseclickhouseRange22.622.6.6.16
OR
clickhouseclickhouseRange22.722.7.4.16
OR
clickhouseclickhouseRange22.822.8.2.11
OR
clickhouseclickhouseRange22.922.9.1.2603

References

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.5%

Related for CVE-2022-44011