CVE-2018-14672: Path Traversal
Published Aug 15, 2019
·Updated
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
Affected Software
2 affected components
Yandex Clickhouse<18.12.13
Clickhouse Clickhouse<18.12.13
Event History
Aug 15, 2019
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-14672?
The severity of CVE-2018-14672 is considered high due to the potential for arbitrary file reading.
2
How do I fix CVE-2018-14672?
To fix CVE-2018-14672, upgrade ClickHouse to version 18.12.13 or later.
3
What impact does CVE-2018-14672 have on ClickHouse?
CVE-2018-14672 allows an attacker to exploit path traversal vulnerabilities to read sensitive files on the server.
4
Which versions of ClickHouse are affected by CVE-2018-14672?
ClickHouse versions prior to 18.12.13 are affected by CVE-2018-14672.
5
Is CVE-2018-14672 a critical vulnerability in ClickHouse?
Yes, CVE-2018-14672 is considered a critical vulnerability due to its potential exploitation risks.