StackRadar

CVE-2024-23689

Medium

Advisory

Published 12 May 2023In the index since 9 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3
of 17,781 indexed, latest versions
Container images
3
deployed by those charts
Fix available
2 of 2
affected packages

ClickHouse vulnerable to client certificate password exposure in client exception

Carried by container images the latest versions of 3 of 17,781 indexed charts deploy, on 3 images.

Affected packageAffected versionsFixed inImages
clickhouse-clientmaven0.3.2-patch11, 0.4.00.4.62
clickhouse-jdbcmaven0.3.2-patch3-all, 0.4.00.4.62
OSV records
GHSA-g8ph-74m6-8m7r

Charts affected

3 by stars
ChartLatestAffected imagesRadar Score
punchline-javapunchplatform8.1.11 of 1See more

punchline-java punchplatform 8.1.1

1 of the 1 container images this version deploys carry CVE-2024-23689.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
clickhouse-client@0.4.0
clickhouse-jdbc@0.4.0
0.4.6
0.4.6

Open the chart page →

1,995
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2024-23689.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
clickhouse-client@0.3.2-patch11
0.4.6

Open the chart page →

8,804
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2024-23689.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
clickhouse-jdbc@0.3.2-patch3-all
0.4.6

Open the chart page →

13,767

Container images carrying it

3 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.5.11bd5756f6273
clickhouse-client@0.3.2-patch11
0.4.6
1
trinodb/trino:405ee80ab5eeab2
clickhouse-jdbc@0.3.2-patch3-all
0.4.6
1
ghcr.io/punchplatform/punchline-java:8.1.1d46ce7b96482
clickhouse-client@0.4.0
clickhouse-jdbc@0.4.0
0.4.6
0.4.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.