CVE-2019-18657: Medium severity clickhouse vulnerability
Published Oct 31, 2019
·Updated
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
Affected Software
2 affected components
Yandex Clickhouse<19.13.5.44
Clickhouse Clickhouse<19.13.5.44
Remediation
Patch Available
Event History
Oct 31, 2019
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-18657?
CVE-2019-18657 has a medium severity rating due to its potential impact on security through HTTP header injection.
2
How do I fix CVE-2019-18657?
To fix CVE-2019-18657, upgrade ClickHouse to version 19.13.5.44 or later.
3
What versions of ClickHouse are affected by CVE-2019-18657?
CVE-2019-18657 affects ClickHouse versions prior to 19.13.5.44.
4
What kind of vulnerability is CVE-2019-18657?
CVE-2019-18657 is an HTTP header injection vulnerability.
5
Can CVE-2019-18657 be exploited remotely?
Yes, CVE-2019-18657 can be exploited remotely through crafted HTTP requests.