Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-52969

Опубликовано: 23 июн. 2025
Источник: ubuntu
Приоритет: negligible

Описание

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

not-affected

esm-apps/noble

not-affected

jammy

DNE

noble

not-affected

oracular

DNE

plucky

DNE

upstream

not-affected

Показывать по

Связанные уязвимости

nvd
3 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CVSS3: 2.8
github
3 месяца назад

ClickHouse 25.7.1.557 allows low-privileged users to execute shell commands by querying existing Executable() tables created by higher-privileged users. Although the CREATE TABLE privilege is restricted, there is no access control preventing low-privileged users from invoking Executable tables already present in the system. If an attacker can influence the contents of the script referenced by the Executable() engine through writable paths, they may execute controlled commands in the context of the ClickHouse server, leading to privilege escalation and unauthorized code execution. NOTE: the Supplier's position is that these types of executions by low-privileged users are the expected behavior.