PT-2026-49302 · Clickhouse+1 · Clickhouse+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vector versions prior to 0.55.0
Description
The ClickHouse sink contains a SQL/identifier injection flaw. The software escaped the
table identifier but interpolated the database value raw into the INSERT statement, allowing a crafted database value to break out of identifier quoting. This occurs in the KeyPartitioner::partition() function via the set uri query parameter, which could allow attackers to access sensitive database information using crafted SQL statements.Recommendations
Update to version 0.55.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clickhouse
Vector