CVE-2025-1385

Severity CVSS v4.0:
HIGH
Type:
CWE-20 Input Validation
Publication date:
20/03/2025
Last modified:
20/03/2025

Description

When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a specified path and execute it in an isolated process. Combined with the ClickHouse table engine functionality that permits file uploads to specific directories, a misconfigured server can be exploited by an attacker with privilege to access to both table engines to execute arbitrary code on the ClickHouse server.<br /> <br /> You can check if your ClickHouse server is vulnerable to this vulnerability by inspecting the configuration file and confirming if the following setting is enabled:<br /> <br /> <br /> 9019<br />