Back to Vulnerability Directory
HIGHFixed upstream

CVE-2024-6873

ClickHouse: unauthenticated crash or execution redirect through the native interface

Technology

ClickHouse

CVSS Score

8.1 / 10.0

Affected Versions

ClickHouse 23.8 before 23.8.15.35, 24.3 before 24.3.4.147, 24.4 before 24.4.2.141, 24.5 before 24.5.1.1763, 24.6 before 24.6.1.4423

Upstream Fix

23.8.15.35, 24.3.4.147, 24.4.2.141, 24.5.1.1763, 24.6.1.4423

Published

August 1, 2024

OSSeva Coverage

Fixed upstream

Description

A specially crafted request to the native interface can crash the server or redirect its execution flow, limited to a 256-byte range of memory, without authentication. ClickHouse says no working remote code execution has been produced. The CVE record marks versions outside the listed ranges as unknown. NVD has deferred the record; the 8.1 score is ClickHouse's as the CNA.

Upstream record: NVD · CVE.org

Is your ClickHouse deployment affected?

If you're running ClickHouse 23.8 before 23.8.15.35, 24.3 before 24.3.4.147, 24.4 before 24.4.2.141, 24.5 before 24.5.1.1763, 24.6 before 24.6.1.4423, you need this patch. Book a discovery call to get covered.