CVE-2021-42392
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
- Affected products
- Astra Linux, H2 Console, H2 Database, Linuxmint, Ubuntu
- h2database h2
- ≤ 2.0.204
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 63.2% (99th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2022-01-07
CVE-2021-42392 at NVD
2 known exploits for CVE-2021-42392
Proof-of-concept code and exploit modules indexed by Sploitus