Description
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-6566 | In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages. |
References
| Link | Providers |
|---|---|
| https://clickhouse.yandex/docs/en/security_changelog/ |
|
History
Wed, 25 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clickhouse
Clickhouse clickhouse |
|
| CPEs | cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yandex
Yandex clickhouse |
Clickhouse
Clickhouse clickhouse |
Status: PUBLISHED
Assigner: yandex
Published:
Updated: 2024-08-05T09:38:13.336Z
Reserved: 2018-07-27T00:00:00.000Z
Link: CVE-2018-14672
No data.
Status : Modified
Published: 2019-08-15T18:15:13.930
Modified: 2025-06-25T20:48:54.637
Link: CVE-2018-14672
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD