CVE-2023-48298

MEDIUM

Clickhouse < 23.3.17.13 - Integer Underflow

Title source: rule
STIX 2.1

Description

ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered and exploited by an unauthenticated attacker. The vulnerability is very similar to CVE-2023-47118 with how the vulnerable function can be exploited.

Scores

CVSS v3 5.9
EPSS 0.0047
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-191
Status published
Products (2)
clickhouse/clickhouse 23.3 - 23.3.17.13
clickhouse/clickhouse_cloud 23.9 - 23.9.2.47475
Published Dec 21, 2023
Tracked Since Feb 18, 2026