Описание
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
Ссылки
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 0.9.5697 (исключая)
Одно из
cpe:2.3:a:cognitect:datomic:*:*:*:*:*:*:*:*
cpe:2.3:a:h2database:h2:1.4.197:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.53325
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
EPSS
Процентиль: 98%
0.53325
Средний
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20