Back to Vulnerability Directory
HIGHFixed upstream

CVE-2022-44010

ClickHouse: unauthenticated heap buffer overflow through the HTTP endpoint

Technology

ClickHouse

CVSS Score

7.5 / 10.0

Affected Versions

ClickHouse before 22.3.12.19, 22.6 before 22.6.6.16, 22.7 before 22.7.4.16, 22.8 before 22.8.2.11, 22.9 before 22.9.1.2603

Upstream Fix

22.3.12.19, 22.6.6.16, 22.7.4.16, 22.8.2.11, 22.9.1.2603

Published

November 23, 2023

OSSeva Coverage

Fixed upstream

Description

A crafted HTTP request to the HTTP endpoint, port 8123 by default, causes a heap-based buffer overflow that crashes the server process. No authentication is required.

Upstream record: NVD · CVE.org

Is your ClickHouse deployment affected?

If you're running ClickHouse before 22.3.12.19, 22.6 before 22.6.6.16, 22.7 before 22.7.4.16, 22.8 before 22.8.2.11, 22.9 before 22.9.1.2603, you need this patch. Book a discovery call to get covered.