Security Advisory

CVE-2018-14672

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-08-15 17:54:05
Last updated 2024-08-05 09:38:13
Assigner yandex
CVSS score not scored
State PUBLISHED

Description

In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.