Описание
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
A flaw was found in the H2 Console. This flaw allows remote attackers to execute arbitrary code via a JDBC URL, concatenating with a substring that allows remote code execution by using a script.
Отчет
In OpenShift Container Platform (OCP) the openshift-enterprise-3.11/metrics-hawkular-metrics-container container image ships a vulnerable version of h2 as part of the underlying images, but as it uses standard configuration and Console is not enabled/started by default, therefore the impact by this vulnerability is LOW and will not be fixed as OCP 3.x has already reached End of Full Support. [1] https://access.redhat.com/support/policy/updates/openshift_noncurrent
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | h2 | Out of support scope | ||
| Red Hat build of Apicurio Registry 2 | h2 | Fix deferred | ||
| Red Hat Decision Manager 7 | h2 | Not affected | ||
| Red Hat Integration Camel K 1 | h2 | Not affected | ||
| Red Hat Integration Camel Quarkus 1 | h2 | Not affected | ||
| Red Hat JBoss BRMS 5 | h2 | Out of support scope | ||
| Red Hat JBoss BRMS 6 | h2 | Out of support scope | ||
| Red Hat JBoss Data Grid 7 | h2 | Out of support scope | ||
| Red Hat JBoss Data Virtualization 6 | h2 | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 6 | h2 | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
H2 Console before 2.1.210 allows remote attackers to execute arbitrary ...
Уязвимость системы управления базами данных H2 , связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3