CVE-2024-6873
ClickHouse: unauthenticated crash or execution redirect through the native interface
Technology
ClickHouse
CVSS Score
8.1 / 10.0
Affected Versions
ClickHouse 23.8 before 23.8.15.35, 24.3 before 24.3.4.147, 24.4 before 24.4.2.141, 24.5 before 24.5.1.1763, 24.6 before 24.6.1.4423
Upstream Fix
23.8.15.35, 24.3.4.147, 24.4.2.141, 24.5.1.1763, 24.6.1.4423
Published
August 1, 2024
OSSeva Coverage
Fixed upstream
Description
A specially crafted request to the native interface can crash the server or redirect its execution flow, limited to a 256-byte range of memory, without authentication. ClickHouse says no working remote code execution has been produced. The CVE record marks versions outside the listed ranges as unknown. NVD has deferred the record; the 8.1 score is ClickHouse's as the CNA.
Is your ClickHouse deployment affected?
If you're running ClickHouse 23.8 before 23.8.15.35, 24.3 before 24.3.4.147, 24.4 before 24.4.2.141, 24.5 before 24.5.1.1763, 24.6 before 24.6.1.4423, you need this patch. Book a discovery call to get covered.