CVE Database
/

CVE-2019-15024

Back to search

CVE-2019-15024

Published: Dec 30, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available from the network where ClickHouse runs, can create a custom-built malicious server that will act as a ClickHouse replica and register it in ZooKeeper. When another replica will fetch data part from the malicious replica, it can force clickhouse-server to write to arbitrary path on filesystem.

VendorProductVersions

n/a

ClickHouse

affected
All versions prior to version 19.14.3.

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now