Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2024-22412

ClickHouse: query cache bypasses role-based access control

Technology

ClickHouse

CVSS Score

4.9 / 10.0

Affected Versions

ClickHouse 23.1 and later before the fixed releases

Upstream Fix

23.3.22.3, 23.8.12.13, 23.12.6.19, 24.1.1.2048

Published

March 18, 2024

OSSeva Coverage

Fixed upstream

Description

The query cache separates results only by user, not by role, so a user who switches roles can receive results cached under another role and see data that role's policies should hide. ClickHouse advises not using the query cache where applications switch roles dynamically on affected versions.

Upstream record: NVD · CVE.org

Is your ClickHouse deployment affected?

If you're running ClickHouse 23.1 and later before the fixed releases, you need this patch. Book a discovery call to get covered.