CVE-2025-52969: Low severity Clickhouse Clickhouse vulnerability
Published Jun 23, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
Clickhouse Clickhouse
Event History
Jun 23, 2025
CVE Published
via MITRE·12:00 AM
Rejected
via MITRE·12:00 AM
Data Sourced
via NVD·05:15 PM
Description
Jul 3, 2025
Rejected
via MITRE·03:20 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-52969?
CVE-2025-52969 is considered a high severity vulnerability due to its potential for low-privileged users to execute arbitrary shell commands.
2
How do I fix CVE-2025-52969?
To fix CVE-2025-52969, restrict access to Executable() tables and ensure proper permissions are enforced for low-privileged users.
3
What software is affected by CVE-2025-52969?
CVE-2025-52969 affects ClickHouse version 25.7.1.557 and potentially earlier versions.
4
What is the exploit mechanism for CVE-2025-52969?
CVE-2025-52969 exploits the lack of access control allowing low-privileged users to query Executable() tables created by privileged users.
5
How can I mitigate the risks associated with CVE-2025-52969?
To mitigate risks from CVE-2025-52969, regularly review user privileges and limit access to systems and tables that can execute shell commands.