PT-2021-6811 · Yandex+1 · Clickhouse+1
Xi-Tauw
·
Published
2021-04-12
·
Updated
2023-08-08
·
CVE-2021-25263
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ClickHouse versions prior to v20.8.18.32-lts
ClickHouse versions prior to v21.1.9.41-stable
ClickHouse versions prior to v21.2.9.41-stable
ClickHouse versions prior to v21.3.6.55-lts
ClickHouse versions prior to v21.4.3.21-stable
Yandex Browser for Windows versions prior to 21.9.0.390
Description
The issue is related to information disclosure and allows a remote attacker to access confidential data. It also involves a local privilege vulnerability that enables a local, low-privileged attacker to execute arbitrary code with SYSTEM privileges by manipulating files in a directory with insecure permissions during the update process of Yandex Browser. An attacker with CREATE DICTIONARY privilege can read arbitrary files outside the permitted directory.
Recommendations
For ClickHouse versions prior to v20.8.18.32-lts, update to version v20.8.18.32-lts or later.
For ClickHouse versions prior to v21.1.9.41-stable, update to version v21.1.9.41-stable or later.
For ClickHouse versions prior to v21.2.9.41-stable, update to version v21.2.9.41-stable or later.
For ClickHouse versions prior to v21.3.6.55-lts, update to version v21.3.6.55-lts or later.
For ClickHouse versions prior to v21.4.3.21-stable, update to version v21.4.3.21-stable or later.
For Yandex Browser for Windows versions prior to 21.9.0.390, update to version 21.9.0.390 or later.
As a temporary workaround, consider restricting the CREATE DICTIONARY privilege to minimize the risk of exploitation.
Fix
Information Disclosure
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clickhouse
Yandex Browser