ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer overflow in decompression of FPC codec. It can be triggered and exploited by an unauthenticated attacker. The vulnerability is very similar to CVE-2023-47118 with how the vulnerable function can be exploited.
Conclusion & alert: CVE-2023-48298 is rated Moderate Risk (45.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.47%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.78% | 0.47% | -0.32% |
| 2 | 2025-11-18 | 0.47% | 0.78% | +0.32% |
| 3 | 2025-04-15 | — | 0.47% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2023-48298 unimportant priority: Debian including 1 source packages (clickhouse), 2 status rows across 2 suites (bookworm, bullseye): resolved 2. | https://security-tracker.debian.org/tracker/CVE-2023-48298 |
ubuntu
|
medium | CVE-2023-48298 medium priority: Ubuntu including 1 source packages (clickhouse), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 5, DNE 4, needs-triage 3. | https://ubuntu.com/security/CVE-2023-48298 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| clickhouse | clickhouse | >= 23.3, <= 23.3.17.13 | cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* |
| clickhouse | clickhouse | >= 23.8, <= 23.8.7.24 | cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* |
| clickhouse | clickhouse | >= 23.9, <= 23.9.5.29 | cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* |
| clickhouse | clickhouse | >= 23.10, <= 23.10.4.25 | cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* |
| clickhouse | clickhouse_cloud | >= 23.9, <= 23.9.2.47475 | cpe:2.3:a:clickhouse:clickhouse_cloud:*:*:*:*:*:*:*:* |