Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3p77-wg4c-qm24 | Exposure of sensitive information in ClickHouse |
Github GHSA |
GHSA-g8ph-74m6-8m7r | ClickHouse vulnerable to client certificate password exposure in client exception |
Sat, 29 Nov 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message. | Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message. |
Fri, 30 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-29T02:03:14.990Z
Reserved: 2024-01-19T17:35:14.200Z
Link: CVE-2024-23689
Updated: 2024-08-01T23:06:25.396Z
Status : Modified
Published: 2024-01-19T21:15:10.520
Modified: 2025-11-29T03:15:57.783
Link: CVE-2024-23689
No data.
OpenCVE Enrichment
No data.
Github GHSA