Lucene search

K
cvelistYandexCVELIST:CVE-2019-15024
HistoryDec 30, 2019 - 2:39 p.m.

CVE-2019-15024

2019-12-3014:39:00
yandex
www.cve.org

0.001 Low

EPSS

Percentile

22.9%

In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available from the network where ClickHouse runs, can create a custom-built malicious server that will act as a ClickHouse replica and register it in ZooKeeper. When another replica will fetch data part from the malicious replica, it can force clickhouse-server to write to arbitrary path on filesystem.

CNA Affected

[
  {
    "product": "ClickHouse",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to version 19.14.3."
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

22.9%

Related for CVELIST:CVE-2019-15024