Go back

ClickHouse Client Certificate Password Exposure

severity
medium
date
Affecting
  • com.clickhouse:clickhouse-r2dbc versions less than 0.4.6

  • com.clickhouse:clickhouse-jdbc versions less than 0.4.6

  • com.clickhouse:clickhouse-client versions less than 0.4.6

CVE
CVE-2024-23689
CVE type
Generation of Error Message Containing Sensitive Information
CVSS
4.8
CVSS V3 Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L