Beschreibung
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse-s PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pg_execute_server_program permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in PostgreSQL (https://www.postgresql.org/about/news/cve-2019-9193-not-a-security-vulnerability-1935/).
CVSS 9.1EPSS 0.515%Risiko 0.95
Quelle öffnen- Veröffentlicht
- 2026-07-29 17:16:52
- Betroffene Versionen
- <=26.3.9.8
- Typ
- Kritische Software
- Zuletzt geändert
- 2026-08-06 09:16:36
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N