CVE-2024-23689: ClickHouse Client Certificate Password Exposure

Published May 12, 2023
·
Updated

Summary As initially reported in issue #1331, when client certificate authentication is enabled with password protection, the password (referred to as the client option sslkey) may be exposed in client exceptions (e.g., ClickHouseException or SQLException). This vulnerability can potentially lead to unauthorized access, data breaches, and violations of user privacy.

Details During the handling of ClickHouseException, the client certificate password may be inadvertently exposed when sslkey is specified. This issue can arise when an exception is thrown during the execution of a query or a database operation. The client certificate password is then included in the exception message, which could be logged or exposed to unauthorized parties.

Impact This vulnerability enables an attacker with access to client exception error messages or logs to obtain client certificate passwords, potentially allowing unauthorized access to sensitive information, data manipulation, and denial of service attacks. The extent of the risk depends on the specific implementation and usage of the affected systems. However, any exposure of client certificate passwords should be treated as a high-priority security concern.

Other sources

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message.

NVD

Exposure of sensitive information in exceptions in ClickHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message.

GitHub

Affected Software

4 affected componentsFixes available
Clickhouse Java Libraries<0.4.6
maven/com.clickhouse:clickhouse-client<0.4.6
0.4.6
maven/com.clickhouse:clickhouse-jdbc<0.4.6
0.4.6
maven/com.clickhouse:clickhouse-r2dbc<0.4.6
0.4.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/com.clickhouse:clickhouse-client to a version that resolves this vulnerability.

    Fixed in 0.4.6
  2. Upgrade

    Upgrade maven/com.clickhouse:clickhouse-jdbc to a version that resolves this vulnerability.

    Fixed in 0.4.6
  3. Upgrade

    Upgrade maven/com.clickhouse:clickhouse-r2dbc to a version that resolves this vulnerability.

    Fixed in 0.4.6
  4. Upgrade

    Upgrade com.clickhouse:clickhouse-r2dbc / com.clickhouse:clickhouse-jdbc / com.clickhouse:clickhouse-client to a version that resolves this vulnerability.

    Fixed in 0.4.6
  5. Configuration

    If possible in your application, avoid setting the client certificate password via the client option `sslkey`; the issue occurs when `sslkey` is specified and an exception (e.g., ClickHouseException or SQLException) is thrown, causing the password to be included in logged exception messages.

    ClickHouse client certificate authentication sslkey = unspecified/avoid when client certificate password protection is enabled
  6. Compensating control

    Treat client exception logs/error message outputs as sensitive: restrict access to logs that may contain client exception messages so unauthorized users cannot view exception details that may include the client certificate password.

Event History

May 12, 2023
Advisory Published
via GitHub·08:18 PM
Data Sourced
via GitHub·08:18 PM
DescriptionSeverityWeaknessAffected Software
Jan 19, 2024
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:30 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-23689?

CVE-2024-23689 is assessed to have a high severity due to the potential exposure of sensitive information.

2

How do I fix CVE-2024-23689?

To fix CVE-2024-23689, upgrade the affected software components to version 0.4.6 or later.

3

Which versions are affected by CVE-2024-23689?

CVE-2024-23689 affects versions of com.clickhouse:clickhouse-client, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-r2dbc that are lower than 0.4.6.

4

What kind of information is exposed in CVE-2024-23689?

CVE-2024-23689 allows unauthorized users to gain access to client certificate passwords via client exception logs.

5

What software components are involved in CVE-2024-23689?

CVE-2024-23689 involves com.clickhouse:clickhouse-client, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-r2dbc.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203