Intel

AIKIDO-2024-10238

github.com/Clickhouse/Clickhouse-go/v2 is vulnerable to Uncaught Exception

Uncaught Exception Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 2, 2024

25

Low Risk

This Affects:

gogithub.com/Clickhouse/Clickhouse-go/v2
2.0.0 - 2.28.1
Fixed in 2.28.2
Are you affected? Scan for Free

TL;DR

Affected versions of the package throw uncaught exceptions. The stdlib driver attempts to use a database connection without verifying its condition, leading to unexpected errors. Attackers can exploit this by inserting illegal statements, causing the connection to close and potentially crashing the program.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/Clickhouse/Clickhouse-go/v2 is vulnerable to Uncaught Exception in versions 2.0.0 - 2.28.1.

How to fix this

Upgrade the github.com/Clickhouse/Clickhouse-go/v2 library to the patch version.