CVE-2018-14669: Infoleak
Published Aug 15, 2019
·Updated
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.
Affected Software
2 affected components
Yandex Clickhouse<1.1.54390
Clickhouse Clickhouse<1.1.54390
Event History
Aug 15, 2019
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-14669?
CVE-2018-14669 is classified as a high severity vulnerability due to its potential for unauthorized data access.
2
How do I fix CVE-2018-14669?
To fix CVE-2018-14669, update the ClickHouse MySQL client to version 1.1.54390 or later.
3
What does CVE-2018-14669 allow attackers to do?
CVE-2018-14669 allows attackers to read arbitrary files from the connected ClickHouse server using the "LOAD DATA LOCAL INFILE" functionality.
4
Which versions of ClickHouse are affected by CVE-2018-14669?
CVE-2018-14669 affects ClickHouse MySQL client versions prior to 1.1.54390.
5
Is CVE-2018-14669 related to file access vulnerabilities?
Yes, CVE-2018-14669 is specifically related to file access vulnerabilities through malicious MySQL database interactions.