CVE-2024-22412

CVSS 3.1 Score 2.4 of 10 (low)

Details

Published Mar 18, 2024
Updated: Mar 19, 2024
CWE ID 863

Summary

CVE-2024-22412 is a vulnerability affecting the open-source database management system ClickHouse, specifically its cloud offering and version 23.1 of the github repository, prior to version 24.0.2.54535. The issue involves bypassed access controls in query caching, which undermines the intended role-based restrictions. In these vulnerable versions, query caching disregards role-based access, a behavior that is not documented or expected. This can result in unauthorized data access for users relying on ClickHouse roles. Attackers with control over a role can potentially guess queries and gain access to information they should not have access to. Version 24.1 of ClickHouse and version 24.0.2.54535 of ClickHouse Cloud have been released with patches to address this issue, and it is recommended to apply these updates to ensure enforced role-based access control, regardless of query caching status.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-22412 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions