Uncontrolled Search Path Element Affecting clickhouse/clickhouse package, versions [,24.3.18.7)[24.4.1.2088,24.8.14.39)[24.9.1.1,24.11.5.49)[24.12.1.1,24.12.5.81)[25.1.1.1,25.1.5.31)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-CLICKHOUSECLICKHOUSE-9576385
  • published1 Apr 2025
  • disclosed20 Mar 2025
  • creditArseniy Dugin

Introduced: 20 Mar 2025

CVE-2025-1385  (opens in a new tab)
CWE-427  (opens in a new tab)

How to fix?

Upgrade clickhouse/clickhouse to version 24.3.18.7, 24.8.14.39, 24.11.5.49, 24.12.5.81, 25.1.5.31 or higher.

Overview

Affected versions of this package are vulnerable to Uncontrolled Search Path Element in the library bridge feature, which exposes an HTTP API on localhost. An attacker who has privileges to upload a malicious library can cause the library to be loaded and executed, if the library bridge feature (<library_bridge>) is enabled and the server is configured insecurely.

References

CVSS Base Scores

version 4.0
version 3.1