CVE-2019-18657 (NVD)

2019-10-31

ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.

Products Clickhouse
Type Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') (CWE-74)
First patch - None (likely due to unavailable code)
Links https://github.com/ClickHouse/ClickHouse/pull/7526/files
https://github.com/ClickHouse/ClickHouse/blob/master/CHANGELOG.md
https://github.com/ClickHouse/ClickHouse/pull/6466