CVE-2022-23221
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
- Affected products
- Astra Linux, H2 Console, H2 Database Console, Linuxmint, Ubuntu
- h2database h2
- < 2.0.206
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 64.8% (99th percentile)
- Weakness
- CWE-88
- NVD status
- Modified
- Published
- 2022-01-19
CVE-2022-23221 at NVD
3 known exploits for CVE-2022-23221
Proof-of-concept code and exploit modules indexed by Sploitus