QID 375493
Date Published: 2021-04-27
QID 375493: ClickHouse HTTP Header Injection Vulnerability
ClickHouse is an open-source column-oriented DBMS for online analytical processing.
Table function url had the vulnerability allowed the attacker to inject arbitrary HTTP headers in the request.
Affected Versions:
Prior to ClickHouse version 19.13.6.1
QID Detection Logic:
This QID uses command clickhouse-client to get the version from the linux system
Successful exploitation allow attacker to inject arbitrary HTTP headers in the request
Solution
Please refer to advisory clickhouse release 19.13.6.1
Vendor References
- CVE-2019-18657 -
clickhouse.tech/docs/en/whats-new/security-changelog/
CVEs related to QID 375493
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2019-18657 |
|