7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
0.0005 Low
EPSS
Percentile
17.0%
ClickHouse is an open-source column-oriented database management system
that allows generating analytical data reports in real-time. A heap buffer
overflow issue was discovered in ClickHouse server. An attacker could send
a specially crafted payload to the native interface exposed by default on
port 9000/tcp, triggering a bug in the decompression logic of Gorilla codec
that crashes the ClickHouse server process. This attack does not require
authentication. This issue has been addressed in ClickHouse Cloud version
23.9.2.47551 and ClickHouse versions 23.10.5.20, 23.3.18.15, 23.8.8.20, and
23.9.6.20.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 20.04 | noarch | clickhouse | < any | UNKNOWN |
ubuntu | 23.10 | noarch | clickhouse | < any | UNKNOWN |
ubuntu | 24.04 | noarch | clickhouse | < any | UNKNOWN |