v6.1.14
Authentication, audit, and SSRF fixes for the query system.
This release contains bug fixes to Hydrolix v6.1. Refer to the release notes to see other notable feature announcements and information for this version.
Upgrade⚓︎
Don't skip minor versions when upgrading or downgrading
Skipping versions when upgrading or downgrading Hydrolix can result in database schema inconsistencies and cluster instability. Always upgrade or downgrade sequentially through each minor version, moving to every intermediate minor release in turn rather than jumping directly from the starting version to the target.
Point releases are safe to skip. Upgrade through each minor version, using the latest point release of each one. Don't install every point release along the way.
For example, to go from v5.10 to v6.1, upgrade sequentially to v5.11.10 -> v6.0.19 -> v6.1.10. Downgrading works the same way, in reverse.
Apply the new Hydrolix operator⚓︎
If you have a self-managed installation, apply the new operator directly with the kubectl command examples. If you're using Hydrolix-supplied tools to manage your installation, follow the procedure prescribed by those tools.
Changelog⚓︎
Bug fixes⚓︎
Query fixes⚓︎
-
Corrected a flaw in ClickHouse native TCP authentication handling which allowed clients to bypass authentication.
-
Added a tunable to control an unauthenticated Prometheus remote read endpoint on the ClickHouse HTTP service. By default,
enable_prom_readturns off access. The/prom_readendpoint didn't require authentication and allowed SQL queries built from client-supplied parameters. -
Removed query options
hdx_log_queryandhdx_internal_query, which clients could use to bypass query logging or audit records. These query options are now ignored completely. Queries including the options in aSETTINGSclause continue to work. -
Prevented use of network-capable ClickHouse table functions
remote,remoteSecure,mysql,cluster, andclusterAllReplicas. Authenticated users could use these for outbound network connections, a server-side request forgery vulnerability.