CVE-2018-14335
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
- Affected products
- H2
- h2database h2
- = 1.4.197
- Fix
- Available
- CVSS 3.0
- 6.5 MEDIUM
- EPSS
- 13.4% (96th percentile)
- Weakness
- CWE-59, CWE-276
- NVD status
- Modified
- Published
- 2018-07-24
CVE-2018-14335 at NVD
4 known exploits for CVE-2018-14335
Proof-of-concept code and exploit modules indexed by Sploitus