CVE-2023-48704: Unauthenticated heap buffer overflow in Gorrila codec decompression

Published Dec 22, 2023
·
Updated

ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface exposed by default on port 9000/tcp, triggering a bug in the decompression logic of Gorilla codec that crashes the ClickHouse server process. This attack does not require authentication. This issue has been addressed in ClickHouse Cloud version 23.9.2.47551 and ClickHouse versions 23.10.5.20, 23.3.18.15, 23.8.8.20, and 23.9.6.20.

Affected Software

5 affected components
Clickhouse Clickhouse>=23.3<23.3.18.15
Clickhouse Clickhouse>=23.8<23.8.8.20
Clickhouse Clickhouse>=23.9<23.9.6.20
Clickhouse Clickhouse>=23.10<23.10.5.20
Clickhouse ClickHouse Cloud<23.9.2.47551

Event History

Dec 22, 2023
CVE Published
03:18 PM
Data Sourced
03:18 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-48704?

CVE-2023-48704 is classified as a high-severity vulnerability due to the potential for a heap buffer overflow exploitation in ClickHouse.

2

How do I fix CVE-2023-48704?

To fix CVE-2023-48704, you should update to a patched version of ClickHouse that addresses the heap buffer overflow issue.

3

What versions of ClickHouse are affected by CVE-2023-48704?

CVE-2023-48704 affects ClickHouse versions from 23.3.0 to 23.10.5 and ClickHouse Cloud versions prior to 23.9.2.47551.

4

What type of vulnerability is CVE-2023-48704?

CVE-2023-48704 is a heap buffer overflow vulnerability that can be exploited through specially crafted payloads.

5

Can CVE-2023-48704 be exploited remotely?

Yes, CVE-2023-48704 can potentially be exploited remotely through attacks targeting the native interface of the ClickHouse server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203