Overview
About vulnerability
When using the ch-go library, under a specific condition when the query includes a large, uncompressed malicious external data, it is possible for an attacker in control of such data to smuggle another query packet into the connection stream.Details
- Affected product:
- ClickHouse/ch-go , Grafana , github.com/ClickHouse/ch-go , github.com/openfga/openfga , github.com/pressly/goose , openfga/openfga , pressly/goose
- Affected packages:
- github.com/ClickHouse/ch-go @ 0.58.2 (+12 more)