Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-47118

Опубликовано: 20 дек. 2023
Источник: nvd
CVSS3: 7
CVSS3: 9.8
EPSS Низкий

Описание

ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface exposed by default on port 9000/tcp, triggering a bug in the decompression logic of T64 codec that crashes the ClickHouse server process. This attack does not require authentication. Note that this exploit can also be triggered via HTTP protocol, however, the attacker will need a valid credential as the HTTP authentication take places first. This issue has been fixed in version 23.10.2.13-stable, 23.9.4.11-stable, 23.8.6.16-lts and 23.3.16.7-lts.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:lts:*:*:*
Версия от 23.3 (включая) до 23.3.16.7 (исключая)
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:lts:*:*:*
Версия от 23.8 (включая) до 23.8.6.16 (исключая)
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Версия от 23.9 (включая) до 23.9.4.11 (исключая)
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Версия от 23.10 (включая) до 23.10.2.13 (исключая)
cpe:2.3:a:clickhouse:clickhouse_cloud:*:*:*:*:*:*:*:*
Версия до 23.9.2.47475 (исключая)

EPSS

Процентиль: 59%
0.00387
Низкий

7 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787

Связанные уязвимости

CVSS3: 7
ubuntu
около 2 лет назад

ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface exposed by default on port 9000/tcp, triggering a bug in the decompression logic of T64 codec that crashes the ClickHouse server process. This attack does not require authentication. Note that this exploit can also be triggered via HTTP protocol, however, the attacker will need a valid credential as the HTTP authentication take places first. This issue has been fixed in version 23.10.2.13-stable, 23.9.4.11-stable, 23.8.6.16-lts and 23.3.16.7-lts.

CVSS3: 7
debian
около 2 лет назад

ClickHouse\xae is an open-source column-oriented database management s ...

EPSS

Процентиль: 59%
0.00387
Низкий

7 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-122
CWE-787