Skip to content

Blackduck: Automated PR: Update com.h2database:h2:1.4.199 to 1.4.200#13

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
BD-PR-h2_1.4.199_com.h2database-1743703473
Open

Blackduck: Automated PR: Update com.h2database:h2:1.4.199 to 1.4.200#13
github-actions[bot] wants to merge 1 commit into
mainfrom
BD-PR-h2_1.4.199_com.h2database-1743703473

Conversation

@github-actions
Copy link
Copy Markdown

@github-actions github-actions Bot commented Apr 3, 2025

Vulnerabilities associated with com.h2database:h2:1.4.199

BDSA-2018-2507 (HIGH): H2 Database's backup function contains an arbitrary file read flaw due to insecure file permissions. This could be exploited by an attacker supplying a specially crafted database file which triggers a symlink attack. If successfully exploited, the user could read protected files on the system without valid permissions.

BDSA-2022-0048 (HIGH): H2 Database is vulnerable to remote code execution (RCE) due to the inclusion of unsafe Java Naming and Directory Interface (JNDI) functionality in its "Console" component. A remote attacker could leverage this functionality in order to load malicious classes into memory.

Note: This is a different vulnerability than CVE-2021-23221 (BDSA-2022-0186).

BDSA-2022-0186 (HIGH): H2 Console (a component of H2 Database) is vulnerable to remote code execution (RCE) due to allowing custom classes to be loaded from remote servers through JNDI (Java Naming and Directory Interface). This can only be exploited if H2 Console has remote access configured and no protection methods are set.

Note: This is a different vulnerability than CVE-2021-42392 (BDSA-2022-0048).

Click Here To See More Details On Server

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants