QID 375496
Date Published: 2021-04-27
QID 375496: ClickHouse Cross Protocol Request Forgery Vulnerability
ClickHouse is an open-source column-oriented DBMS for online analytical processing.
ClickHouse is vulnerable to Cross Protocol Request Forgery Vulnerability
Affected Versions:
Prior to ClickHouse version 1.1.54388
QID Detection Logic:
This QID uses command clickhouse-client to get the version from the linux system
remote table function allowed arbitrary symbols in user, password and default_database fields which led to Cross Protocol Request Forgery Attacks.
Solution
Please refer to advisory clickhouse release 1.1.54390
Vendor References
- ClickHouse 1.1.54388 -
clickhouse.tech/docs/en/whats-new/security-changelog/
CVEs related to QID 375496
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 1.1.54388 |
|