Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-1385

ClickHouse: code execution through the library bridge

Technology

ClickHouse

CVSS Score

7.5 / 10.0

Affected Versions

ClickHouse 24.3 before 24.3.18.6, 24.8 before 24.8.14.27, 24.11 before 24.11.5.34, 24.12 before 24.12.5.65, 25.1 before 25.1.5.5

Upstream Fix

24.3.18.6, 24.8.14.27, 24.11.5.34, 24.12.5.65, 25.1.5.5

Published

March 20, 2025

OSSeva Coverage

Fixed upstream

Description

When the library bridge is enabled, clickhouse-library-bridge exposes an HTTP API on localhost that loads a library from a given path. Combined with table engines that can upload files to specific directories, a user privileged to use both can run code on the server. The advisory says to check whether a library_bridge port is configured. ClickHouse Cloud is not affected. NVD has deferred the record; the 7.5 score is ClickHouse's CVSS 4.0 score as the CNA.

Upstream record: NVD · CVE.org

Is your ClickHouse deployment affected?

If you're running ClickHouse 24.3 before 24.3.18.6, 24.8 before 24.8.14.27, 24.11 before 24.11.5.34, 24.12 before 24.12.5.65, 25.1 before 25.1.5.5, you need this patch. Book a discovery call to get covered.