Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22wj-vf5f-wrvj

Опубликовано: 23 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Password exposure in H2 Database

The web-based admin console in H2 Database Engine through 2.1.214 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states "This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that."

Пакеты

Наименование

com.h2database:h2

maven
Затронутые версииВерсия исправления

>= 1.4.198, < 2.2.220

2.2.220

EPSS

Процентиль: 28%
0.00099
Низкий

7.8 High

CVSS3

Дефекты

CWE-200
CWE-312

Связанные уязвимости

CVSS3: 8.4
ubuntu
почти 3 года назад

The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states "This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that." Nonetheless, the issue was fixed in 2.2.220.

CVSS3: 8.4
nvd
почти 3 года назад

The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states "This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that." Nonetheless, the issue was fixed in 2.2.220.

CVSS3: 8.4
debian
почти 3 года назад

The web-based admin console in H2 Database Engine before 2.2.220 can b ...

CVSS3: 8.4
fstec
почти 3 года назад

Уязвимость веб-интерфейса системы управления базами данных H2, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 28%
0.00099
Низкий

7.8 High

CVSS3

Дефекты

CWE-200
CWE-312