Security Advisory

CVE-2021-42392

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-01-07 00:00:00
Last updated 2024-08-04 03:30:38
Assigner JFROG
State PUBLISHED

Description

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.