Database/Control plane, storage & DevOps
ClickHouse: Second heap out-of-bounds read in LZ4::decompressImpl reachable from a client query
CVSS 8.1CVE-2021-42388Control plane, storage & DevOpscurated
Impact
Second heap out-of-bounds read in LZ4::decompressImpl reachable from a client query
Who can reach it
Network (remote)
What to do
Control-plane: upgrade; require auth on the native port
References
Related entries
- ClickHouse: Attacker-controlled offset in the LZ4 codecCVE-2021-42387 · ClickHouseHigh
- HTCondor (condor_schedd, condor_collector): A user with nothing more than READ access to the schedd or collector canCVE-2021-45101 · HTCondor (condor_schedd, condor_collector)High
- HTCondor (S3 file transfer, daemon logs and job ClassAds): Pre-signed S3 URLs for a job's input and output are writtenCVE-2021-45103 · HTCondor (S3 file transfer, daemon logs and job ClassAds)High
- NetApp ONTAP SnapLock on FlexGroup volumes: An authenticated remote user modifies or deletes WORM-locked data beforeCVE-2022-23241 · NetApp ONTAP SnapLock on FlexGroup volumesHigh
- Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - Device File Transfer settings: MissingCVE-2023-25552 · Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - Device File Transfer settingsHigh
- Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2a: Remote unauthenticated users can bypass webCVE-2023-31424 · Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2aHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.