Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

clickhouse — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in clickhouse, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for ClickHouse, a column-oriented database management system developed by ClickHouse Inc., focusing on Common Weakness Enumerations (CWE) tags. It collects security advisories and reported vulnerabilities affecting the ClickHouse product, covering historical records and updates from its initial public releases through recent versions. Visitors can use this resource to track vendor-specific advisories as they are published, gain a deeper understanding of specific weakness classes within the context of database systems, and look up a comprehensive history of vulnerabilities associated with the product over time. The data includes details on impact, affected versions, and mitigation strategies where available, providing a centralized view of the security landscape for this open-source analytics database. This aggregation aims to assist security professionals, developers, and administrators in assessing risks, prioritizing patches, and maintaining the integrity of their data infrastructure. By consolidating information from various sources, the page simplifies the process of staying informed about emerging threats and known issues. Users can search by specific weakness types or browse the chronological list to identify patterns or recurring problem areas. This approach supports proactive security management by highlighting past incidents that may inform future development and configuration practices. The information presented here is intended to facilitate better decision-making regarding software maintenance and security hardening for deployments of ClickHouse.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2024-6873 Specially crafted request could caused undefined behaviour which may lead to Remote Code Execution. CWE-122 8.1 High2024-08-01
CVE-2024-22412 ClickHouse's Role-based Access Control is bypassed when query caching is enabled. CWE-863 2.4 Low2024-03-18
CVE-2023-48704 Unauthenticated heap buffer overflow in Gorrila codec decompression CWE-122 7.0 High2023-12-22
CVE-2023-48298 Integer underflow leading to stack overflow in FPC codec decompression CWE-191 5.9 Medium2023-12-21
CVE-2023-47118 Heap buffer overflow in T64 codec decompression CWE-122 7.0 High2023-12-20
CVE-2021-42391 Yandex ClickHouse 数字错误漏洞 CWE-369 6.5 -2022-03-14
CVE-2021-42390 Yandex ClickHouse 数字错误漏洞 CWE-369 6.5 -2022-03-14
CVE-2021-42389 Yandex ClickHouse 数字错误漏洞 CWE-369 6.5 -2022-03-14
CVE-2021-42388 Yandex ClickHouse 缓冲区错误漏洞 CWE-125 8.1 -2022-03-14
CVE-2021-42387 Yandex ClickHouse 缓冲区错误漏洞 CWE-125 8.1 -2022-03-14
CVE-2021-43304 Yandex ClickHouse 缓冲区错误漏洞 CWE-122 8.8 -2022-03-14
CVE-2021-43305 Yandex ClickHouse 缓冲区错误漏洞 CWE-122 8.8 -2022-03-14
CVE-2019-15024 Yandex ClickHouse 输入验证错误漏洞 6.5 -2019-12-30
CVE-2019-16535 Yandex ClickHouse 缓冲区错误漏洞 9.8 -2019-12-30
CVE-2018-14672 Yandex ClickHouse 路径遍历漏洞 7.5 -2019-08-15
CVE-2018-14671 Yandex ClickHouse 输入验证错误漏洞 9.8 -2019-08-15
CVE-2018-14669 ClickHouse MySQL client 信息泄露漏洞 7.5 -2019-08-15
CVE-2018-14668 Yandex ClickHouse 跨站请求伪造漏洞 8.8 -2019-08-15
CVE-2018-14670 Yandex ClickHouse 授权问题漏洞 9.8 -2019-08-15

All 19 known CVE vulnerabilities affecting clickhouse with full Chinese analysis, references, and POCs where available.