CVE-2024-22412
CVSS 3.1 Score 2.4 of 10 (low)
Details
Summary
CVE-2024-22412 is a vulnerability affecting the open-source database management system ClickHouse, specifically its cloud offering and version 23.1 of the github repository, prior to version 24.0.2.54535. The issue involves bypassed access controls in query caching, which undermines the intended role-based restrictions. In these vulnerable versions, query caching disregards role-based access, a behavior that is not documented or expected. This can result in unauthorized data access for users relying on ClickHouse roles. Attackers with control over a role can potentially guess queries and gain access to information they should not have access to. Version 24.1 of ClickHouse and version 24.0.2.54535 of ClickHouse Cloud have been released with patches to address this issue, and it is recommended to apply these updates to ensure enforced role-based access control, regardless of query caching status.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.