← Back

CVE-2021-42392

nvd nist
Published: Jan 10, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

Affected (5)

1 product
H2
1 product
Debian Linux
1 product
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.1.000 to 2.0.204
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 9.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.15.0

References (14)

Source: reefs@jfrog.com
ExploitTechnical DescriptionVendor Advisory
Source: reefs@jfrog.com
Mailing ListThird Party Advisory
Source: reefs@jfrog.com
Third Party Advisory
Source: reefs@jfrog.com
Third Party Advisory
Source: reefs@jfrog.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.