PT-2019-9041 · Yandex · Clickhouse

Published

2019-08-15

·

Updated

2025-06-25

·

CVE-2018-14670

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClickHouse versions prior to 1.1.54131
Description The issue is related to an incorrect configuration in the deb package, which could allow unauthorized use of the database.
Recommendations For versions prior to 1.1.54131, update to version 1.1.54131 or later to resolve the issue.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2018-14670

Affected Products

Clickhouse