CVE-2023-48704 - CVE House
Back to Database
Status published High CVE-2023-48704

Unauthenticated heap buffer overflow in Gorrila codec decompression

Vulnerability Description

ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially crafted payload to the native interface exposed by default on port 9000/tcp, triggering a bug in the decompression logic of Gorilla codec that crashes the ClickHouse server process. This attack does not require authentication. This issue has been addressed in ClickHouse Cloud version 23.9.2.47551 and ClickHouse versions 23.10.5.20, 23.3.18.15, 23.8.8.20, and 23.9.6.20.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-48704

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ClickHouse
Vulnerable Versions:
< 23.9.2.47551, < 23.10.5.20, < 23.3.18.15, < 23.8.8.20, < 23.9.6.20

Timeline

Official Publish: December 22nd, 2023
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Weaknesses (CWE)