Thursday, January 30, 2025
HomeCyber Security NewsDeepSeek Database Publicly Exposed Sensitive Information, Secret Keys & Logs

DeepSeek Database Publicly Exposed Sensitive Information, Secret Keys & Logs

Published on

SIEM as a Service

Follow Us on Google News

Experts at Wiz Research have identified a publicly exposed ClickHouse database belonging to DeepSeek, a Chinese AI startup renowned for its innovative models.

The vulnerability granted full control over database operations, exposing sensitive information such as chat history, secret keys, backend details, and over a million lines of log streams.

The issue was responsibly disclosed to DeepSeek, and the company has since secured the database.

DeepSeek has been under the spotlight recently due to its cutting-edge AI models, particularly the DeepSeek-R1 reasoning model.

plain text chat messages from deepseek
plain text chat messages from deepseek

The model has been touted as a major rival to systems like OpenAI’s o1, excelling in performance, cost-effectiveness, and efficiency.

As the company’s stature grew, the Wiz Research team prioritized examining its external security posture to identify vulnerabilities—ultimately discovering this serious lapse.

A Publicly Accessible ClickHouse Database

During their investigation, Wiz Research found the ClickHouse database hosted at two accessible endpoints:

  • http://oauth2callback.deepseek.com:9000
  • http://dev.deepseek.com:9000

Despite its immense importance, the database was completely open, requiring no authentication whatsoever.

client servers on port 9000
client servers on port 9000

The exposed ClickHouse environment allowed not only unrestricted access but also the potential for privilege escalation across DeepSeek’s internal systems.

What Was Exposed?

The exposed database included a massive treasure trove of sensitive data, with a critical table named log_stream standing out. This table alone contained over one million log entries with revealing data, including:

  • Timestamps: Logs dating back to January 6, 2025.
  • API Secrets & Keys: Plaintext API keys and backend operational details.
  • Chat History: Logs of customer interactions and metadata.
  • Internal Service Metadata: Information about services generating the logs.
  • File Details: Possible access to proprietary files and plaintext passwords.

The exposure posed not only a risk to DeepSeek’s infrastructure but also to the privacy and security of its end-users.

ClickHouse, a popular open-source database used for real-time data processing and analytics, is powerful yet vulnerable to misconfigurations.

The /play path within ClickHouse’s HTTP interface allowed arbitrary SQL queries to be executed directly via a browser. With a query as simple as SHOW TABLES, the Wiz team gained access to the database structure.

Queries could even exfiltrate sensitive files depending on ClickHouse’s configuration.

HTTP interface allowed arbitrary SQL queries to be executed directly via a browser
HTTP interface allowed arbitrary SQL queries to be executed directly via a browser

This breach is a stark reminder for organizations leveraging powerful tools like ClickHouse. Misconfigurations can leave critical infrastructure exposed, opening doors for attackers.

The need for robust security mechanisms, such as authentication, role-based access control, and regular audits, cannot be overstated.

Upon being informed by Wiz Research, DeepSeek acted swiftly to secure the exposed database. While the immediate threat has been mitigated, this incident highlights the ever-present risks inherent in managing large-scale AI systems and data.

The DeepSeek database exposure underlines a critical call to action for companies worldwide: as systems become more powerful and interconnected, robust security must be the foundation of every operation.

Collect Threat Intelligence with TI Lookup to improve your company’s security - Get 50 Free Request

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently...

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton...

Arcus Media Ransomware Strikes: Files Locked, Backups Erased, and Remote Access Disabled

The cybersecurity landscape faces increasing challenges as Arcus Media ransomware emerges as a highly...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Hackers Exploiting DNS Poisoning to Compromise Active Directory Environments

A groundbreaking technique for Kerberos relaying over HTTP, leveraging multicast poisoning, has been recently...

New Android Malware Exploiting Wedding Invitations to Steal Victims WhatsApp Messages

Since mid-2024, cybersecurity researchers have been monitoring a sophisticated Android malware campaign dubbed "Tria...

500 Million Proton VPN & Pass Users at Risk Due to Memory Protection Vulnerability

Proton, the globally recognized provider of privacy-focused services such as Proton VPN and Proton...