CVE-2025-1385
ClickHouse: code execution through the library bridge
Technology
ClickHouse
CVSS Score
7.5 / 10.0
Affected Versions
ClickHouse 24.3 before 24.3.18.6, 24.8 before 24.8.14.27, 24.11 before 24.11.5.34, 24.12 before 24.12.5.65, 25.1 before 25.1.5.5
Upstream Fix
24.3.18.6, 24.8.14.27, 24.11.5.34, 24.12.5.65, 25.1.5.5
Published
March 20, 2025
OSSeva Coverage
Fixed upstream
Description
When the library bridge is enabled, clickhouse-library-bridge exposes an HTTP API on localhost that loads a library from a given path. Combined with table engines that can upload files to specific directories, a user privileged to use both can run code on the server. The advisory says to check whether a library_bridge port is configured. ClickHouse Cloud is not affected. NVD has deferred the record; the 7.5 score is ClickHouse's CVSS 4.0 score as the CNA.
Is your ClickHouse deployment affected?
If you're running ClickHouse 24.3 before 24.3.18.6, 24.8 before 24.8.14.27, 24.11 before 24.11.5.34, 24.12 before 24.12.5.65, 25.1 before 25.1.5.5, you need this patch. Book a discovery call to get covered.