QID 375497
Date Published: 2021-04-27
QID 375497: ClickHouse Information Exposure Vulnerability
ClickHouse is an open-source column-oriented DBMS for online analytical processing.
ClickHouse is vulnerable toInformation Exposure Vulnerability
Affected Versions:
Prior to ClickHouse version 1.1.54390
QID Detection Logic:
This QID uses command clickhouse-client to get the version from the linux system
Successful exploitation could allow malicious MySQL database read arbitrary files from the connected ClickHouse server.
Solution
Please refer to advisory clickhouse release 1.1.54390
Vendor References
- ClickHouse 1.1.54390 -
clickhouse.tech/docs/en/whats-new/security-changelog/
CVEs related to QID 375497
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ClickHouse 1.1.54390 |
|