QID 375495
Date Published: 2021-04-27
QID 375495: ClickHouse Remote Code Execution Vulnerability
ClickHouse is an open-source column-oriented DBMS for online analytical processing.
ClickHouse is vulnerable to Remote Code Execution Vulnerability
Affected Versions:
Prior to ClickHouse version 18.10.3
QID Detection Logic:
This QID uses command clickhouse-client to get the version from the linux system
Successful exploitation could allow remote code execution
Solution
Please refer to advisory clickhouse release 18.10.3
Vendor References
- ClickHouse Release 18.10.3 -
clickhouse.tech/docs/en/whats-new/security-changelog/
CVEs related to QID 375495
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ClickHouse Release 18.10.3 |
|