« Volver al listado

CVE-2024-23689

Estado: ModificadaAlta (8.8)—

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-23689",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-23689",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-09T23:56:00.497117Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "disclosure@vulncheck.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.4.6",
              "versionType": "maven"
            }
          ],
          "packageURL": "pkg:maven/com.clickhouse/clickhouse-r2dbc",
          "packageName": "com.clickhouse:clickhouse-r2dbc",
          "collectionURL": "https://repo.maven.apache.org/maven2",
          "defaultStatus": "unaffected"
        },
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.4.6",
              "versionType": "maven"
            }
          ],
          "packageURL": "pkg:maven/com.clickhouse/clickhouse-jdbc",
          "packageName": "com.clickhouse:clickhouse-jdbc",
          "collectionURL": "https://repo.maven.apache.org/maven2",
          "defaultStatus": "unaffected"
        },
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.4.6",
              "versionType": "maven"
            }
          ],
          "packageURL": "pkg:maven/com.clickhouse/clickhouse-client",
          "packageName": "com.clickhouse:clickhouse-client",
          "collectionURL": "https://repo.maven.apache.org/maven2",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-01-19T21:15:10.520",
  "references": [
    {
      "url": "https://github.com/ClickHouse/clickhouse-java/issues/1331",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://github.com/ClickHouse/clickhouse-java/pull/1334",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://github.com/ClickHouse/clickhouse-java/releases/tag/v0.4.6",
      "tags": [
        "Release Notes"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://github.com/ClickHouse/clickhouse-java/security/advisories/GHSA-g8ph-74m6-8m7r",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://github.com/advisories/GHSA-g8ph-74m6-8m7r",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-g8ph-74m6-8m7r",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://github.com/ClickHouse/clickhouse-java/issues/1331",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/ClickHouse/clickhouse-java/pull/1334",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/ClickHouse/clickhouse-java/releases/tag/v0.4.6",
      "tags": [
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/ClickHouse/clickhouse-java/security/advisories/GHSA-g8ph-74m6-8m7r",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/advisories/GHSA-g8ph-74m6-8m7r",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://vulncheck.com/advisories/vc-advisory-GHSA-g8ph-74m6-8m7r",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosure@vulncheck.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-209"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-209"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message."
    },
    {
      "lang": "es",
      "value": "La exposición de información confidencial en excepciones en las versiones clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc y com.clickhouse:clickhouse-client de ClichHouse inferiores a 0.4.6 permite a usuarios no autorizados obtener acceso a las contraseñas de los certificados del cliente a través de los registros de excepciones del cliente. Esto ocurre cuando se especifica 'sslkey' y se genera una excepción, como ClickHouseException o SQLException, durante las operaciones de la base de datos; la contraseña del certificado se incluye en el mensaje de excepción registrado."
    }
  ],
  "lastModified": "2026-07-14T23:17:17.523",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:clickhouse:java_libraries:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7EFEC79-6EFB-4FCD-A772-C6A600512D6A",
              "versionEndExcluding": "0.4.6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosure@vulncheck.com"
}