ALT-PU-2019-2809-1
Package clickhouse updated to version 19.13.5.44-alt1 for branch sisyphus in task 238181.
Closed vulnerabilities
Published: 2019-10-31
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-18657
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
References:
- https://github.com/ClickHouse/ClickHouse/blob/master/CHANGELOG.md
- https://github.com/ClickHouse/ClickHouse/blob/master/CHANGELOG.md
- https://github.com/ClickHouse/ClickHouse/pull/6466
- https://github.com/ClickHouse/ClickHouse/pull/6466
- https://github.com/ClickHouse/ClickHouse/pull/7526/files
- https://github.com/ClickHouse/ClickHouse/pull/7526/files