CVE-2018-14668: CSRF
Published Aug 15, 2019
·Updated
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "defaultdatabase" fields which led to Cross Protocol Request Forgery Attacks.
Affected Software
2 affected components
Yandex Clickhouse<1.1.54388
Clickhouse Clickhouse<1.1.54388
Event History
Aug 15, 2019
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-14668?
CVE-2018-14668 is considered a moderate severity vulnerability due to its potential for Cross Protocol Request Forgery Attacks.
2
How do I fix CVE-2018-14668?
To fix CVE-2018-14668, upgrade ClickHouse to version 1.1.54388 or later.
3
What types of attacks are associated with CVE-2018-14668?
CVE-2018-14668 can lead to Cross Protocol Request Forgery Attacks due to improper validation of user input.
4
Which versions of ClickHouse are affected by CVE-2018-14668?
CVE-2018-14668 affects ClickHouse versions prior to 1.1.54388.
5
What components of ClickHouse does CVE-2018-14668 impact?
CVE-2018-14668 impacts the 'remote' table function in ClickHouse.