← Back

CVE-2021-23463

nvd nist
Published: Dec 10, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

Affected (1)

Products: H2database: H2
1 product
H2
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.4.198 to 2.0.202

References (12)

Source: report@snyk.io
ExploitIssue TrackingPatchThird Party Advisory
Source: report@snyk.io
Issue TrackingPatchThird Party Advisory
Source: report@snyk.io
ExploitPatchThird Party Advisory
Source: report@snyk.io
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.