{"id":"GHSA-3p77-wg4c-qm24","summary":"Duplicate Advisory: Exposure of sensitive information in ClickHouse","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-g8ph-74m6-8m7r. This link is maintained to preserve external references.\n\n## Original Description\nExposure of sensitive information in exceptions in ClickHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message.","modified":"2026-08-24T00:35:42.510104906Z","published":"2024-01-19T21:30:36Z","withdrawn":"2026-01-22T20:36:05Z","database_specific":{"nvd_published_at":"2024-01-19T21:15:10Z","cwe_ids":["CWE-209"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-01-23T14:34:54Z"},"references":[{"type":"WEB","url":"https://github.com/ClickHouse/clickhouse-java/security/advisories/GHSA-g8ph-74m6-8m7r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23689"},{"type":"WEB","url":"https://github.com/ClickHouse/clickhouse-java/issues/1331"},{"type":"WEB","url":"https://github.com/ClickHouse/clickhouse-java/pull/1334"},{"type":"PACKAGE","url":"https://github.com/ClickHouse/clickhouse-java"},{"type":"WEB","url":"https://github.com/ClickHouse/clickhouse-java/releases/tag/v0.4.6"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g8ph-74m6-8m7r"},{"type":"WEB","url":"https://vulncheck.com/advisories/vc-advisory-GHSA-g8ph-74m6-8m7r"}],"affected":[{"package":{"name":"com.clickhouse:clickhouse-r2dbc","ecosystem":"Maven","purl":"pkg:maven/com.clickhouse/clickhouse-r2dbc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.6"}]}],"versions":["0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-3p77-wg4c-qm24/GHSA-3p77-wg4c-qm24.json"}},{"package":{"name":"com.clickhouse:clickhouse-jdbc","ecosystem":"Maven","purl":"pkg:maven/com.clickhouse/clickhouse-jdbc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.6"}]}],"versions":["0.3.2","0.3.2-patch1","0.3.2-patch10","0.3.2-patch11","0.3.2-patch2","0.3.2-patch3","0.3.2-patch4","0.3.2-patch5","0.3.2-patch6","0.3.2-patch7","0.3.2-patch8","0.3.2-patch9","0.3.2-test1","0.3.2-test2","0.3.2-test3","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-3p77-wg4c-qm24/GHSA-3p77-wg4c-qm24.json"}},{"package":{"name":"com.clickhouse:clickhouse-client","ecosystem":"Maven","purl":"pkg:maven/com.clickhouse/clickhouse-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.6"}]}],"versions":["0.3.2","0.3.2-patch1","0.3.2-patch10","0.3.2-patch11","0.3.2-patch2","0.3.2-patch3","0.3.2-patch4","0.3.2-patch5","0.3.2-patch6","0.3.2-patch7","0.3.2-patch8","0.3.2-patch9","0.3.2-test1","0.3.2-test2","0.3.2-test3","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.4.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-3p77-wg4c-qm24/GHSA-3p77-wg4c-qm24.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}