CVE-2025-1385
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
20/03/2025
Last modified:
20/03/2025
Description
When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a specified path and execute it in an isolated process. Combined with the ClickHouse table engine functionality that permits file uploads to specific directories, a misconfigured server can be exploited by an attacker with privilege to access to both table engines to execute arbitrary code on the ClickHouse server.<br />
<br />
You can check if your ClickHouse server is vulnerable to this vulnerability by inspecting the configuration file and confirming if the following setting is enabled:<br />
<br />
<br />
9019<br />
Impact
Base Score 4.0
7.50
Severity 4.0
HIGH