Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-44010

Опубликовано: 23 нояб. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on port 8123 by default), causing a heap-based buffer overflow that crashes the process. This does not require authentication. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Версия до 22.3.12.19 (исключая)
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Версия от 22.6 (включая) до 22.6.6.16 (исключая)
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Версия от 22.7 (включая) до 22.7.4.16 (исключая)
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Версия от 22.8 (включая) до 22.8.2.11 (исключая)
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Версия от 22.9 (включая) до 22.9.1.2603 (исключая)

EPSS

Процентиль: 54%
0.00313
Низкий

7.5 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 лет назад

An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on port 8123 by default), causing a heap-based buffer overflow that crashes the process. This does not require authentication. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

CVSS3: 7.5
debian
около 2 лет назад

An issue was discovered in ClickHouse before 22.9.1.2603. An attacker ...

CVSS3: 7.5
github
около 2 лет назад

An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on port 8123 by default), causing a heap-based buffer overflow that crashes the process. This does not require authentication. The fixed versions are 22.9.1.2603, 22.8.2.11, 22.7.4.16, 22.6.6.16, and 22.3.12.19.

EPSS

Процентиль: 54%
0.00313
Низкий

7.5 High

CVSS3

Дефекты

CWE-787