1 results (0.002 seconds)
CVSS: 9.8EPSS: 0%CPEs: 5EXPL: 0

CVE-2025-1385 – Fail input validation in clickhouse-library-bridge API could lead to RCE under specific configuration
https://notcve.org/view.php?id=CVE-2025-1385
20 Mar 2025 — When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a specified path and execute it in an isolated process. Combined with the ClickHouse table engine functionality that permits file uploads to specific directories, a misconfigured server can be exploited by an attacker with privilege to access to both table engines to execute arbitrary code on the ClickHouse server. You can check if your ... • https://github.com/ClickHouse/ClickHouse/security/advisories/GHSA-5phv-x8x4-83x5 • CWE-20: Improper Input Validation •