{"id":"7906d9fe-23b7-4795-b287-2beeeeea7b2a","engagementId":"5d104649-f358-49e5-a0a6-403df2ec4df1","data":{"brief":{"id":"8de45876-a46a-4e03-a206-6ab9aea08c5a","name":"ClickHouse","tagline":"ClickHouse is an open-source, column-oriented OLAP database management system that allows users to generate analytical reports using SQL queries in real-time","description":"\u003cp\u003eNo technology is perfect and ClickHouse believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our open-source assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of ClickHouse not listed in the targets section is out of scope. This includes any/all subdomains not listed here. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to ClickHouse, you can report it here. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eTesting Setup and Reporting\u003c/h1\u003e\n\n\u003ch2\u003eClickHouse OSS target\u003c/h2\u003e\n\n\u003cp\u003eWe recommend researchers to follow the \u003ca href=\"https://clickhouse.com/docs/en/quick-start\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003equickstart guide\u003c/a\u003e  to familiarize themselves with \u003ccode\u003eclickhouse-client\u003c/code\u003e and \u003ccode\u003eclickehouse-server\u003c/code\u003e. To test out specific feature flags \u0026amp; security flags, we recommend going through our documentation at \u003ca href=\"https://clickhouse.com/docs/en/intro\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://clickhouse.com/docs/en/intro\u003c/a\u003e for more information. \u003c/p\u003e\n\n\u003cp\u003eIf finding a bug requires a special testing methodology or tools, we would appreciate it if these will be described in the report, so we can triage the issue quicker and improve our infrastructure. If the report covers mitigation guidelines or a fix, it is also appreciated.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eHigh Level Example of a Report:\u003c/strong\u003e \u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003e**Lab setup**:\n- ClickHouse server version - Release v22.6.1.1985-stable\n- ClickHouse client version - Release v22.6.1.1985-stable\n- Host: Ubuntu Server 20.04\n- Platform: x86_64\n\n**Additional Setup**:\n- The `encryption_codecs` inside `/etc/clickhouse-server/config.yaml` must use **aes_128_gcm_siv** key.\n- Created an user and granted access to select `GRANT SELECT(x,y) ON db.table TO user1 WITH GRANT OPTION` so user1 can query x and y columns and able to grant access to these columns to other users according to \u0026lt;https://clickhouse.com/docs/en/sql-reference/statements/grant/\u0026gt;\n\n**Exploitation**:\n- Detail step 1\n- Detail step 2\n\n**Outcome**:\n- User1 was able to access other columns and bypass the restrictions placed on their account.\n\n**Extra Details**:\n- Crashlog of the application.\n- Proof of concept code/queries ran.\n- Methodology or tools used to identify the issue\n- Mitigation guidelines\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cp\u003e\u003cstrong\u003eFocus Areas:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBypasses against Role Based Access Control management.\u003c/li\u003e\n\u003cli\u003eBypasses against any additional security controls implemented in ClickHouse (this may require specific setup with understanding of ClickHouse and various security configurations such as enabling mTLS, encryption).\u003c/li\u003e\n\u003cli\u003eVarious memory corruption and buffer overflow vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eClickHouse Cloud Platform target\u003c/h2\u003e\n\n\u003cp\u003eSecurity researchers can start testing by registering for a free account at https://clickhouse.com/ by using an @bugcrowdninja email address. Your account will come with $300 worth of testing credits. Do not use unlimited credit cards or throw away cards. This behavior will result in removal from the program.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFocus Areas:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIDOR\u003c/li\u003e\n\u003cli\u003eInjection\u003c/li\u003e\n\u003cli\u003eStored XSS\u003c/li\u003e\n\u003cli\u003eServer-side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eSensitive data exposure\u003c/li\u003e\n\u003cli\u003eBusiness logic flaws\u003c/li\u003e\n\u003cli\u003eRemote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eAuthentication related issues\u003c/li\u003e\n\u003cli\u003eAuthorization related issues\u003c/li\u003e\n\u003cli\u003eUnauthorized API actions\u003c/li\u003e\n\u003cli\u003eClever vulnerabilities that bypass our security controls \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eExcluded Submission Types\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eLack of rate limiting\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eMissing security deaders\u003c/li\u003e\n\u003cli\u003eEXIF geolocation data\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF/DKIM/DMARC records\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure\u003c/li\u003e\n\u003cli\u003ePOST-based reflected XSS / self XSS\u003c/li\u003e\n\u003cli\u003eSocial engineering and physical attacks\u003c/li\u003e\n\u003cli\u003eAny customer hosted systems or services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf during your testing you discover exposed internal credentials, achieve unauthorized access to internal systems, or identify a vulnerability that could lead to internal system compromise, immediately cease testing and report your findings. We will assess the full impact of your discovery and ensure you receive the maximum applicable reward based on the potential severity. Any attempts to further enumerate, perform lateral movement, or escalate access after discovering such  vulnerabilities will be considered a violation of this program's rules resulting in forfeiture of all rewards and potential removal from the program.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"aea844a8-2802-4d9b-84ad-f6469c0e17ee","name":"ClickHouse Cloud Platform target","targets":[{"id":"b7c197d9-64f2-4a90-ad0b-1f08e0adeefe","uri":"https://clickhou.se/bugcrowd","name":"https://clickhou.se/bugcrowd","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8a69afd4-8956-4447-a9df-d540b462108a","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b7c197d9-64f2-4a90-ad0b-1f08e0adeefe"}],"recentChangeFlags":null},{"id":"a92d5460-4e1e-4fe5-a0e1-7ba8efa0f799","uri":"","name":"ClickHouse Cloud environment hosted by ClickHouse","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5b2989b8-d66d-435b-80bb-83cc80413081","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c7f8276e-01a7-4db1-bc67-4514174e12dd","p1MaxCents":250000,"p1MinCents":210000,"p2MaxCents":125000,"p2MinCents":100000,"p3MaxCents":60000,"p3MinCents":10000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eClickHouse Cloud is our SaaS platform which provides users with a managed ClickHouse service with seamless scaling and serverless operations. ClickHouse Cloud consists of several components. The Control Plane web application allows users to manage user access, start/stop instances, monitor usage information and configure advanced features such as IP Filtering, Advanced Scaling etc. The Data Plane and its components manage and store customers’ ClickHouse services and data.\u003c/p\u003e\n\n\u003ch3\u003eDocumentation:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://clickhou.se/bugcrowddocs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://clickhou.se/bugcrowddocs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eSpecial requirements and guidelines:\u003c/h3\u003e\n\n\u003cp\u003eClickHouse is updated regularly. Keep an eye out on their Security Policy page \u003ca href=\"https://github.com/ClickHouse/ClickHouse/security/policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/ClickHouse/ClickHouse/security/policy\u003c/a\u003e in order to ensure you are testing on a supported version. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSecurity researchers must ensure the registration email for their testing account is a bugcrowd email address ending with @bugcrowdninja.com. For more info regarding bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eIf you find a vulnerability that exposes customer or employee personal information, stop testing and report the issue immediately.\u003c/li\u003e\n\u003cli\u003eIf you find a vulnerability that allows you to gain shell access to our environment, stop testing and report the issue immediately.\u003c/li\u003e\n\u003cli\u003eDo not purposefully attempt to degrade systems or services during testing.\u003c/li\u003e\n\u003cli\u003eOnly target your own account and do not attempt to access data from anyone else’s account that you do not explicitly own.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReporting requirements:\u003c/h3\u003e\n\n\u003cp\u003eResearchers must follow \u003ca href=\"https://docs.bugcrowd.com/researchers/reporting-managing-submissions/reporting-a-bug/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eguidelines\u003c/a\u003e from Bugcrowd in reporting a security vulnerability and the report must describe the vulnerability in detail, where it was discovered, the steps to reproduce and, most importantly, the potential impact of exploitation.\u003c/p\u003e","rewardRangeData":{"1":{"min":2100,"max":2500},"2":{"min":1000,"max":1250},"3":{"min":100,"max":600},"4":{"min":50,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"79e64982-fa2a-4b3a-a984-21558066b4cd","name":"ClickHouse OSS target","targets":[{"id":"199729cb-9883-4dad-8b71-7dc9c45979f0","uri":"https://github.com/ClickHouse/ClickHouse","name":"https://github.com/ClickHouse/ClickHouse","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"35c58386-f008-4913-aca5-68ccbe39f6f5","sortOrder":0},"sortOrder":0,"tags":[{"id":"86402f5d-20d0-4c88-92b9-0994786e4241","name":"C++","targetId":"199729cb-9883-4dad-8b71-7dc9c45979f0"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"9d98e671-f426-4f65-a213-a701378a9229","p1MaxCents":125000,"p1MinCents":105000,"p2MaxCents":62500,"p2MinCents":50000,"p3MaxCents":30000,"p3MinCents":5000,"p4MaxCents":5000,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eThe source code is written in C++. ClickHouse is an open-source column-oriented DBMS (columnar database management system) for online analytical processing (OLAP), which allows users to generate analytical reports using SQL queries in real-time. The main focus of the public program is the open source version of the ClickHouse platform available at https://github.com/ClickHouse/ClickHouse. The repository contains source code for both the ClickHouse server and client(s) components. The ClickHouse software binaries can be downloaded from https://clickhouse.com/.\u003c/p\u003e\n\n\u003ch3\u003eDocumentation:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://clickhouse.com/docs/en/intro\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://clickhouse.com/docs/en/intro\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eSupported Versions:\u003c/h3\u003e\n\n\u003cp\u003eClickHouse is updated regularly. Keep an eye out on our Security Policy page \u003ca href=\"https://github.com/ClickHouse/ClickHouse/security/policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/ClickHouse/ClickHouse/security/policy\u003c/a\u003e in order to ensure you are testing on a supported version. \u003c/p\u003e\n\n\u003ch3\u003eReporting Requirements\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eResearchers must follow \u003ca href=\"https://docs.bugcrowd.com/researchers/reporting-managing-submissions/reporting-a-bug/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eguidelines\u003c/a\u003e from Bugcrowd in reporting a security vulnerability. Due to the nature of this specific target, the following are additional requirements to be qualified for a bug bounty:\u003c/li\u003e\n\u003cli\u003eThe report should contain a description of the error and step-by-step instructions for reproducing it.\u003c/li\u003e\n\u003cli\u003eThe issue should be reproducible in the latest official release and the latest build from master.\u003c/li\u003e\n\u003cli\u003eUnmodified source code and binaries have to be used in reproducing scenarios.\u003c/li\u003e\n\u003cli\u003eThe issue should not be already published. If the issue is already found by another researcher, it is not qualified for bug bounty program.\u003c/li\u003e\n\u003cli\u003eThe issue should be reproducible on Linux, x86_64 platform and should not depend on the Linux kernel version, libc version and configuration of environment like DNS resolvers, SSL certificates, filesystem and block devices configuration, etc. It should not depend on hardware failures.\u003c/li\u003e\n\u003cli\u003eThe issue should be reproducible without installation of additional software on the machines with clickhouse-server.\u003c/li\u003e\n\u003cli\u003eIf the issue requires usage of features marked as experimental in the documentation or code or enabling experimental flags (settings, configurations), it is not qualified for the bug bounty program.\u003c/li\u003e\n\u003cli\u003eThe issue should be reproducible with release builds from ClickHouse CI infrastructure. Debug and sanitized builds, builds with another compiler or compiler options are not qualified.\u003c/li\u003e\n\u003cli\u003eThe issue should be related to the clickhouse-server component.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":1050,"max":1250},"2":{"min":500,"max":625},"3":{"min":50,"max":300},"4":{"min":0,"max":50},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"29f4809d-3cd9-49e6-818b-0d4b173a0c09","name":"Langfuse Cloud Platform ","targets":[{"id":"58d45d5a-4a6f-4908-8258-b635741efb52","uri":"","name":"https://cloud.langfuse.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"aee3008c-4a65-42a9-a531-41a1145b5352","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"c7f8276e-01a7-4db1-bc67-4514174e12dd","p1MaxCents":250000,"p1MinCents":210000,"p2MaxCents":125000,"p2MinCents":100000,"p3MaxCents":60000,"p3MinCents":10000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003e\u003ca href=\"https://langfuse.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eLangfuse\u003c/a\u003e is an open source LLM engineering platform. Langfuse helps you ship AI Agents/Products from prototype to production and beyond. Once in production, it powers your continuous improvement loop using production data to make your agents and LLM applications even more powerful.\u003c/p\u003e\n\n\u003ch3\u003eDocumentation:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSource code: \u003ca href=\"https://github.com/langfuse/langfuse\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/langfuse/langfuse\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://langfuse.com/docs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://langfuse.com/docs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://langfuse.com/security/responsible-disclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://langfuse.com/security/responsible-disclosure\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReporting Requirements\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSecurity researchers must ensure the registration email for their testing account is a bugcrowd email address ending with @bugcrowdninja.com. For more info regarding bugcrowdninja email addresses, see here.\u003c/li\u003e\n\u003cli\u003eIf you find a vulnerability that exposes customer or employee personal information, stop testing and report the issue immediately.\u003c/li\u003e\n\u003cli\u003eIf you find a vulnerability that allows you to gain shell access to our environment, stop testing and report the issue immediately.\u003c/li\u003e\n\u003cli\u003eDo not purposefully attempt to degrade systems or services during testing.\u003c/li\u003e\n\u003cli\u003eOnly target your own account and do not attempt to access data from anyone else’s account that you do not explicitly own.\u003c/li\u003e\n\u003cli\u003eResearchers must follow \u003ca href=\"https://docs.bugcrowd.com/researchers/reporting-managing-submissions/reporting-a-bug/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eguidelines\u003c/a\u003e from Bugcrowd in reporting a security vulnerability.\u003c/li\u003e\n\u003cli\u003eThe report should contain a clear description of the vulnerability including its potential impact, steps to reproduce (including any specific configurations or conditions required), and any proof-of-concept code, scripts, or screenshots that demonstrate the vulnerability.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":2100,"max":2500},"2":{"min":1000,"max":1250},"3":{"min":100,"max":600},"4":{"min":50,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"989aaafa-7597-462e-abce-04d542da4dc3","name":"Out of Scope","targets":[{"id":"f322b318-6244-4390-9a51-b4e2dca1eac6","uri":"","name":"New support cases, Chat, Request new integration form","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9cae5188-1c42-47c1-80e0-ff350655686b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"05bbd9eb-7d99-4a75-be0b-eba4574822b0","uri":"","name":"Share feedback form","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5f18292c-5b50-4151-831a-a8bfb3cdd41e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"e4474452-d60a-4082-ac29-22a9cfea7706","uri":"","name":"Vulnerability scanners","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2a3ffc64-3b4e-424d-a920-3ff50848f08f","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"26aa3e65-a046-479e-b693-ea7c431b6319","uri":"https://learn.clickhouse.com/","name":"learn.clickhouse.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0400aba9-679d-484e-a3bf-94bbd37c8c8c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"26aa3e65-a046-479e-b693-ea7c431b6319"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":3,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003e\u003cstrong\u003eImportant\u003c/strong\u003e: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNew support cases, Chat, Request new integration form\u003c/strong\u003e and \u003cstrong\u003eShare feedback\u003c/strong\u003e form are no longer included in target scope as these actions can generate unnecessary noises for our support team.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePostgres offering\u003c/strong\u003e: The Postgres offering of ClickHouse allows users to interact with the underlying system by design given it\u0026#39;s full tenant isolation. Do not report such findings unless there is a potential impact to escalate outside the tenant permission boundaries. \u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eDo not use vulnerability scanners on this program\u003c/strong\u003e. The use of custom scripts and fuzzing tools on this program must be targeted, specific testing, and then only at less than five requests per second to reduce noise and minimize potential disruption for our customers.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eResults from a static code analysis tool with no manual verification or a proof of concept.\u003c/li\u003e\n\u003cli\u003eA list of out-of-date dependencies - chances are we are aware of this and the team is making efforts to update them accordingly without introducing any breaking changes. If you think a particular vulnerability is severe and exploitable from the way it is implemented in the ClickHouse codebase, please provide a proof of concept.\u003c/li\u003e\n\u003cli\u003eTheoretical security issues.\u003c/li\u003e\n\u003cli\u003eWeb vulnerabilities against the built-in “play” HTTP server with the default local setup and no real-world impact (e.g. clickjacking, CSRF, missing security headers, etc.)\u003c/li\u003e\n\u003cli\u003eThird party websites or systems hosted by non-ClickHouse entities that ClickHouse staff use\u003c/li\u003e\n\u003cli\u003eDoS / DDoS attacks that may cause disruption to our service\u003c/li\u003e\n\u003cli\u003ePayment processing (handled by a third party)\u003c/li\u003e\n\u003cli\u003eSocial Engineering\u003c/li\u003e\n\u003cli\u003eInternal information such as users or processes in the \u003ccode\u003esystem.*\u003c/code\u003e tables that cannot be exploited or do not leak actionable sensitive information\u003c/li\u003e\n\u003cli\u003eMissing rate limiting without demonstrating a concrete security impact\u003c/li\u003e\n\u003cli\u003eAutomated scanner output without manual verification or a working proof of concept\u003c/li\u003e\n\u003cli\u003eMissing security headers (e.g., CSP, X-Frame-Options) without a demonstrated exploit, or missing Secure/HttpOnly flag on non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eTesting that would result in sending spam or other unsolicited messages to users\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of ClickHouse not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to ClickHouse, you can report it here. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"5d104649-f358-49e5-a0a6-403df2ec4df1","code":"clickhouse","state":"in_progress","endsAt":null,"bountyId":"d9904b8d-4bad-4586-94fe-c696d6b31527","startsAt":"2022-06-28T00:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/4ad3/c3db/f62a98b3/06fc777db185b87f5039424a9e573dbf_ch_logo_yellow_on_black.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-06-28T00:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/clickhouse","changelogs":"/engagements/clickhouse/changelog","submissions":null,"announcements":"/engagements/clickhouse/announcements","hallOfFame":"/engagements/clickhouse/hall_of_fames","crowdstream":"/engagements/clickhouse/crowdstream"},"announcementsCount":6,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/clickhouse/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=clickhouse\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/clickhouse/engagement_subscribers","engagementChangelogsUrl":"/engagements/clickhouse/changelog","publishedAt":"2026-08-24T06:02:00.354Z","engagementChangelogUrl":"/engagements/clickhouse/changelog/7906d9fe-23b7-4795-b287-2beeeeea7b2a","createUserFeedbacksUrl":"/engagements/clickhouse/feedbacks","engagementCrowdstreamUrl":"/engagements/clickhouse/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}