Skip to content

Security: DougTidwell/ClickHouse

Security

SECURITY.md

Altinity Security Policy

We're extremely grateful for security researchers and users that report vulnerabilities to the ClickHouse Open Source Community in general and Altinity in particular. All reports are thoroughly investigated by developers.

Reporting a Vulnerability

To report a potential vulnerability, send the details of the potential vulnerability to [email protected].

When Should I Report a Vulnerability?

  • You think you discovered a potential security vulnerability in an Altinity Stable Build
  • You are unsure how a vulnerability affects ClickHouse or an Altinity Stable Build

When Should I NOT Report a Vulnerability?

  • You need help tuning your system for security
  • You need help applying security related updates
  • Your issue is not security related

Security Vulnerability Response

Each report sent to Altinity is acknowledged and analyzed within five working days. The result of our analysis may be to pass the report on to ClickHouse.com, at which point their security policies apply.

Public Disclosure Timing

If the vulnerability is verified as a threat and it applies only to code maintained by Altinity, a public disclosure date will be negotiated by Altinity and the bug submitter. We prefer to fully disclose the vulnerability as soon as possible once a user mitigation is available. It is reasonable to delay disclosure when the vulnerability, fix, or mitigation is not yet fully understood, the solution is not well-tested, or for vendor coordination. The timeframe for disclosure is from immediate (especially if it's already publicly known) to 90 days. For a vulnerability with a straightforward mitigation, we expect the report date to disclosure date to be on the order of 7 days.

Scope and Supported Versions

The following versions of Altinity Stable Builds are currently being supported with security updates:

Altinity Stable Build release Last update Supported?
23.8.11.29.altinitystable 2024-04-30
23.3.19.34.altinityfips 2024-03-21
23.3.19.33.altinitystable 2023-08-24
22.8.20.12.altinitystable 2023-08-24
22.8.15.25.altinityfips 2023-05-31
22.3.15.34.altinitystable 2022-12-22
21.8.15.15.altinitystable 2022-08-15
21.3.20.2.altinitystable 2022-02-10
21.1.11.3.altinitystable 2022-06-01
20.8.11.17.altinitystable 2020-12-25
20.3.19.4.altinitystable 2020-09-23
19.16.19.85.altinitystable 2020-04-20
19.13.7.57.altinitystable 2019-11-28
19.11.8.altinitystable 2019-09-03
18.14.19.altinitystable 2018-12-31

©2024 Altinity Inc. All rights reserved. Altinity®, Altinity.Cloud®, and Altinity Stable Builds® are registered trademarks of Altinity, Inc. ClickHouse® is a registered trademark of ClickHouse, Inc.

There aren’t any published security advisories