Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.74%
Published
Aug 15, 2019
Modified
Jun 25, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages.
Weaknesses (CWE)
Affected Products (1)
References (2)