ClickHouse kayıtları
clickhouse üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %28
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-369 Divide By Zero3
- CWE-125 Out-of-bounds Read3
- CWE-122 Heap-based Buffer Overflow3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
- CWE-787 Out-of-bounds Write2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-14671İstismar yok | In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vuclickhouse · clickhouse · CWE-20 | Kritik9,8 | — | %3,4 | 15 Ağu 2019 |
40Planlayın | CVE-2018-14670İstismar yok | Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.clickhouse · clickhouse · CWE-285 | Kritik9,8 | — | %1,8 | 15 Ağu 2019 |
40Planlayın | CVE-2019-16535İstismar yok | In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve clickhouse · clickhouse · CWE-125 | Kritik9,8 | — | %1,7 | 30 Ara 2019 |
39İzleyin | CVE-2023-47118İstismar yok | Heap buffer overflow in T64 codec decompressionclickhouse · clickhouse · CWE-122 | Kritik9,8 | — | %0,5 | 20 Ara 2023 |
36İzleyin | CVE-2021-43304İstismar yok | Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query.clickhouse · clickhouse · CWE-122 | Yüksek8,8 | — | %1,7 | 14 Mar 2022 |
36İzleyin | CVE-2021-43305İstismar yok | Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query.clickhouse · clickhouse · CWE-122 | Yüksek8,8 | — | %1,7 | 14 Mar 2022 |
35İzleyin | CVE-2018-14668İstismar yok | In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which clickhouse · clickhouse · CWE-352 | Yüksek8,8 | — | %0,7 | 15 Ağu 2019 |
35İzleyin | CVE-2024-23689İstismar yok | ClickHouse Client Certificate Password Exposureclickhouse · java libraries · CWE-209 | Yüksek8,8 | — | %0,7 | 19 Oca 2024 |
32İzleyin | CVE-2021-42387İstismar yok | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query.clickhouse · clickhouse · CWE-125 | Yüksek8,1 | — | %1,6 | 14 Mar 2022 |
32İzleyin | CVE-2021-42388İstismar yok | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query.clickhouse · clickhouse · CWE-125 | Yüksek8,1 | — | %1,6 | 14 Mar 2022 |
32İzleyin | CVE-2019-16536İstismar yok | Stack overflow leading to DoS can be triggered by a malicious authenticated client.clickhouse · clickhouse · CWE-120 | Yüksek8,2 | — | %0,9 | 21 May 2025 |
31İzleyin | CVE-2018-14669İstismar yok | ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL databaseclickhouse · clickhouse · CWE-200 | Yüksek7,5 | — | %1,7 | 15 Ağu 2019 |
30İzleyin | CVE-2022-44010İstismar yok | An issue was discovered in ClickHouse before 22.9.1.2603.clickhouse · clickhouse · CWE-787 | Yüksek7,5 | — | %1,0 | 23 Kas 2023 |
30İzleyin | CVE-2023-48298İstismar yok | Integer underflow leading to stack overflow in FPC codec decompressionclickhouse · clickhouse · CWE-191 | Yüksek7,5 | — | %0,6 | 21 Ara 2023 |
30İzleyin | CVE-2024-41436İstismar yok | ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.clickhouse · clickhouse · CWE-120 | Yüksek7,5 | — | %0,6 | 3 Eyl 2024 |
30İzleyin | CVE-2023-48704İstismar yok | Unauthenticated heap buffer overflow in Gorrila codec decompressionclickhouse · clickhouse · CWE-120 | Yüksek7,5 | — | %0,5 | 22 Ara 2023 |
26İzleyin | CVE-2021-42391İstismar yok | Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query.clickhouse · clickhouse · CWE-369 | Orta6,5 | — | %1,4 | 14 Mar 2022 |
26İzleyin | CVE-2021-42390İstismar yok | Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query.clickhouse · clickhouse · CWE-369 | Orta6,5 | — | %1,3 | 14 Mar 2022 |
26İzleyin | CVE-2021-42389İstismar yok | Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query.clickhouse · clickhouse · CWE-369 | Orta6,5 | — | %1,3 | 14 Mar 2022 |
26İzleyin | CVE-2019-15024İstismar yok | In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available clickhouse · clickhouse | Orta6,5 | — | %0,9 | 30 Ara 2019 |
26İzleyin | CVE-2022-44011İstismar yok | An issue was discovered in ClickHouse before 22.9.1.2603.clickhouse · clickhouse · CWE-787 | Orta6,5 | — | %0,7 | 23 Kas 2023 |
23İzleyin | CVE-2025-1386İstismar yok | Query smuggling in ch-go libraryclickhouse · ch · CWE-444 | Orta5,9 | — | %0,4 | 11 Nis 2025 |
22İzleyin | CVE-2018-14672İstismar yok | In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messagclickhouse · clickhouse · CWE-22 | Orta5,3 | — | %1,7 | 15 Ağu 2019 |
21İzleyin | CVE-2019-18657İstismar yok | ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.clickhouse · clickhouse · CWE-74 | Orta5,3 | — | %1,5 | 31 Eki 2019 |
19İzleyin | CVE-2024-22412İstismar yok | ClickHouse's Role-based Access Control is bypassed when query caching is enabled.clickhouse · clickhouse · CWE-863 | Orta4,9 | — | %0,6 | 18 Mar 2024 |
- CVE-2018-1467140Planlayın
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vu
KritikCVSS 9,8İstismar yokEPSS %3clickhouse · clickhouse15 Ağu 2019
- CVE-2018-1467040Planlayın
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
KritikCVSS 9,8İstismar yokEPSS %2clickhouse · clickhouse15 Ağu 2019
- CVE-2019-1653540Planlayın
In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve
KritikCVSS 9,8İstismar yokEPSS %2clickhouse · clickhouse30 Ara 2019
- CVE-2023-4711839İzleyin
Heap buffer overflow in T64 codec decompression
KritikCVSS 9,8İstismar yokEPSS %0clickhouse · clickhouse20 Ara 2023
- CVE-2021-4330436İzleyin
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query.
YüksekCVSS 8,8İstismar yokEPSS %2clickhouse · clickhouse14 Mar 2022
- CVE-2021-4330536İzleyin
Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query.
YüksekCVSS 8,8İstismar yokEPSS %2clickhouse · clickhouse14 Mar 2022
- CVE-2018-1466835İzleyin
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which
YüksekCVSS 8,8İstismar yokEPSS %1clickhouse · clickhouse15 Ağu 2019
- CVE-2024-2368935İzleyin
ClickHouse Client Certificate Password Exposure
YüksekCVSS 8,8İstismar yokEPSS %1clickhouse · java libraries19 Oca 2024
- CVE-2021-4238732İzleyin
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query.
YüksekCVSS 8,1İstismar yokEPSS %2clickhouse · clickhouse14 Mar 2022
- CVE-2021-4238832İzleyin
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query.
YüksekCVSS 8,1İstismar yokEPSS %2clickhouse · clickhouse14 Mar 2022
- CVE-2019-1653632İzleyin
Stack overflow leading to DoS can be triggered by a malicious authenticated client.
YüksekCVSS 8,2İstismar yokEPSS %1clickhouse · clickhouse21 May 2025
- CVE-2018-1466931İzleyin
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database
YüksekCVSS 7,5İstismar yokEPSS %2clickhouse · clickhouse15 Ağu 2019
- CVE-2022-4401030İzleyin
An issue was discovered in ClickHouse before 22.9.1.2603.
YüksekCVSS 7,5İstismar yokEPSS %1clickhouse · clickhouse23 Kas 2023
- CVE-2023-4829830İzleyin
Integer underflow leading to stack overflow in FPC codec decompression
YüksekCVSS 7,5İstismar yokEPSS %1clickhouse · clickhouse21 Ara 2023
- CVE-2024-4143630İzleyin
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.
YüksekCVSS 7,5İstismar yokEPSS %1clickhouse · clickhouse3 Eyl 2024
- CVE-2023-4870430İzleyin
Unauthenticated heap buffer overflow in Gorrila codec decompression
YüksekCVSS 7,5İstismar yokEPSS %0clickhouse · clickhouse22 Ara 2023
- CVE-2021-4239126İzleyin
Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query.
OrtaCVSS 6,5İstismar yokEPSS %1clickhouse · clickhouse14 Mar 2022
- CVE-2021-4239026İzleyin
Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query.
OrtaCVSS 6,5İstismar yokEPSS %1clickhouse · clickhouse14 Mar 2022
- CVE-2021-4238926İzleyin
Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query.
OrtaCVSS 6,5İstismar yokEPSS %1clickhouse · clickhouse14 Mar 2022
- CVE-2019-1502426İzleyin
In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available
OrtaCVSS 6,5İstismar yokEPSS %1clickhouse · clickhouse30 Ara 2019
- CVE-2022-4401126İzleyin
An issue was discovered in ClickHouse before 22.9.1.2603.
OrtaCVSS 6,5İstismar yokEPSS %1clickhouse · clickhouse23 Kas 2023
- CVE-2025-138623İzleyin
Query smuggling in ch-go library
OrtaCVSS 5,9İstismar yokEPSS %0clickhouse · ch11 Nis 2025
- CVE-2018-1467222İzleyin
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messag
OrtaCVSS 5,3İstismar yokEPSS %2clickhouse · clickhouse15 Ağu 2019
- CVE-2019-1865721İzleyin
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
OrtaCVSS 5,3İstismar yokEPSS %1clickhouse · clickhouse31 Eki 2019
- CVE-2024-2241219İzleyin
ClickHouse's Role-based Access Control is bypassed when query caching is enabled.
OrtaCVSS 4,9İstismar yokEPSS %1clickhouse · clickhouse18 Mar 2024