CVE Feed

    Dashboard / CVE / CVE-2024-23689

    CVE-2024-23689

    Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message.

    Published:Jan 19, 2024
    Last Modified:Nov 29, 2025
    EPS:Jan 19, 2024
    EPSS Score:0.00965
    CVSS Score:8.8

    Affected Products

    Vendor
    Clickhouse
    Product
    Java Libraries

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High