Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-22412
ClickHouse: query cache bypasses role-based access control
Technology
ClickHouse
CVSS Score
4.9 / 10.0
Affected Versions
ClickHouse 23.1 and later before the fixed releases
Upstream Fix
23.3.22.3, 23.8.12.13, 23.12.6.19, 24.1.1.2048
Published
March 18, 2024
OSSeva Coverage
Fixed upstream
Description
The query cache separates results only by user, not by role, so a user who switches roles can receive results cached under another role and see data that role's policies should hide. ClickHouse advises not using the query cache where applications switch roles dynamically on affected versions.
Is your ClickHouse deployment affected?
If you're running ClickHouse 23.1 and later before the fixed releases, you need this patch. Book a discovery call to get covered.