CVE-2018-14670: Critical severity clickhouse vulnerability
Published Aug 15, 2019
·Updated
Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database.
Affected Software
2 affected components
Yandex Clickhouse<1.1.54131
Clickhouse Clickhouse<1.1.54131
Event History
Aug 15, 2019
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-14670?
CVE-2018-14670 has a medium severity rating due to the risk of unauthorized database access.
2
How do I fix CVE-2018-14670?
To fix CVE-2018-14670, upgrade ClickHouse to version 1.1.54131 or later.
3
What does CVE-2018-14670 affect?
CVE-2018-14670 affects the ClickHouse database due to incorrect configuration in the deb package.
4
Can CVE-2018-14670 lead to data breaches?
Yes, CVE-2018-14670 can lead to unauthorized use of the database, potentially resulting in data breaches.
5
Is CVE-2018-14670 still an issue in the latest ClickHouse versions?
No, CVE-2018-14670 is not an issue in ClickHouse versions 1.1.54131 and above.