• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
multiple flaws uncovered in clickhouse olap database system for big

Multiple Flaws Uncovered in ClickHouse OLAP Database System for Big Data

You are here: Home / General Cyber Security News / Multiple Flaws Uncovered in ClickHouse OLAP Database System for Big Data
March 16, 2022

Scientists have disclosed 7 new security vulnerabilities in an open up-resource database management system option termed ClickHouse that could be weaponized to crash the servers, leak memory contents, and even direct to the execution of arbitrary code.

“The vulnerabilities involve authentication, but can be brought on by any consumer with read through permissions,” Uriya Yavnieli and Or Peles, scientists from DevSecOps firm JFrog, said in a report posted Tuesday.

“This implies the attacker will have to perform reconnaissance on the particular ClickHouse server goal to get legitimate credentials. Any established of qualifications would do, because even a consumer with the cheapest privileges can cause all of the vulnerabilities.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Automatic GitHub Backups

The checklist of 7 flaws is under –

  • CVE-2021-43304 and CVE-2021-43305 (CVSS scores: 8.8) – Heap buffer overflow flaws in the LZ4 compression codec that could lead to distant code execution
  • CVE-2021-42387 and CVE-2021-42388 (CVSS scores: 7.1) – Heap out-of-bounds go through flaws in the LZ4 compression codec that could lead to denial-of-service or information leakage
  • CVE-2021-42389 (CVSS rating: 6.5) – A divide-by-zero flaw in the Delta compression codec that could consequence in a denial-of-assistance ailment
  • CVE-2021-42390 (CVSS rating: 6.5) – A divide-by-zero flaw in the DeltaDouble compression codec that could consequence in a denial-of-company problem
  • CVE-2021-42391 (CVSS score: 6.5) – A divide-by-zero flaw in the Gorilla compression codec that could end result in a denial-of-provider condition

Prevent Data Breaches

An attacker can just take benefit of any of the aforementioned flaws by applying a specifically crafted compressed file to crash a susceptible database server. ClickHouse customers are advisable to improve to version “v21.10.2.15-secure” or later to mitigate the issues.

The findings come a thirty day period just after JFrog disclosed aspects of a higher-severity security vulnerability in Apache Cassandra (CVE-2021-44521, CVSS rating: 8.4) that, if still left unaddressed, could be abused to obtain distant code execution (RCE) on influenced installations.

Identified this short article attention-grabbing? Follow THN on Fb, Twitter  and LinkedIn to examine a lot more unique content material we article.


Some parts of this write-up are sourced from:
thehackernews.com

Previous Post: «facebook hit with $18.6 million gdpr fine over 12 data Facebook Hit With $18.6 Million GDPR Fine Over 12 Data Breaches in 2018
Next Post: German Government Warns Against Using Russia’s Kaspersky Antivirus Software german government warns against using russia's kaspersky antivirus software»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.