QID 375494
Date Published: 2021-04-27
QID 375494: ClickHouse Path Traversal Vulnerability
ClickHouse is an open-source column-oriented DBMS for online analytical processing.
ClickHouse is vulnerable to Path Traversal Vulnerability
Affected Versions:
Prior to ClickHouse version 18.12.13
QID Detection Logic:
This QID uses command clickhouse-client to get the version from the linux system
Successful exploitation could allow path traversal and reading arbitrary files through error messages.
Solution
Please refer to advisory clickhouse release 18.12.13
Vendor References
- ClickHouse 18.12.13 -
clickhouse.tech/docs/en/whats-new/security-changelog/
CVEs related to QID 375494
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2018-14672 |
|