Skip to content

Commit

Permalink
Adding CVE-2024-22412
Browse files Browse the repository at this point in the history
  • Loading branch information
santrancisco authored Mar 26, 2024
1 parent 4ce6dad commit 54eae12
Showing 1 changed file with 11 additions and 0 deletions.
11 changes: 11 additions & 0 deletions docs/en/whats-new/security-changelog.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,17 @@ sidebar_label: Security Changelog

# Security Changelog

## Fixed in ClickHouse v24.1, 2024-01-30 {#fixed-in-clickhouse-release-24-01-30}

### [CVE-2024-22412](https://github.com/ClickHouse/ClickHouse/security/advisories/GHSA-45h5-f7g3-gr8r) {#CVE-2024-22412}

When toggling between user roles while using ClickHouse with query cache enabled, there is a risk of obtaining inaccurate data. ClickHouse advises users with vulnerable versions of ClickHouse not to use the query cache when their application dynamically switches between various roles.

Fix has been pushed to the following open-source versions: v24.1.1.2048. LTS versions will receive backport fixes in the upcoming release, we are recommending turning off query cache if your application switches between user roles for managing permissions for now.

ClickHouse Cloud uses different versioning and a fix for this vulnerability was applied at v24.0.2.54535.

Credits: Evan Johnson and Alan Braithwaite from RunReveal team

## Fixed in ClickHouse v23.10.5.20, 2023-11-26 {#fixed-in-clickhouse-release-23-10-5-20-2023-11-26}

Expand Down

0 comments on commit 54eae12

Please sign in to comment.