Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-48704

ClickHouse: unauthenticated heap buffer overflow in the Gorilla codec

Technology

ClickHouse

CVSS Score

7.5 / 10.0

Affected Versions

ClickHouse before 23.3.18.15, 23.8 before 23.8.8.20, 23.9 before 23.9.6.20, 23.10 before 23.10.5.20

Upstream Fix

23.3.18.15, 23.8.8.20, 23.9.6.20, 23.10.5.20

Published

December 22, 2023

OSSeva Coverage

Fixed upstream

Description

A crafted payload sent to the native interface, port 9000/tcp by default, triggers a heap buffer overflow in the Gorilla codec's decompression and crashes the server process without authentication.

Upstream record: NVD · CVE.org

Is your ClickHouse deployment affected?

If you're running ClickHouse before 23.3.18.15, 23.8 before 23.8.8.20, 23.9 before 23.9.6.20, 23.10 before 23.10.5.20, you need this patch. Book a discovery call to get covered.