logoalt Hacker News

matmulslast Wednesday at 10:10 PM1 replyview on HN

ssrf was the entry point, and clickhouse is supposed to be an internal only service, but one could reach it only with that ssrf, so hence less of "scrutiny". The 0day by itself wouldnt be useful, unless an attacker can reach clickhouse, which they usually can't.


Replies

thenaturalistlast Wednesday at 10:39 PM

But if they do, prohibiting SQL injection, a critical last mile vulnerability, seems trivial?

show 3 replies