CVE-2021-42392
Summary
| CVE | CVE-2021-42392 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-10 14:10:00 UTC |
| Updated | 2023-02-24 22:15:00 UTC |
| Description | The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5076-1 h2database |
DEBIAN |
www.debian.org |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| [SECURITY] [DLA 2923-1] h2database security update |
MLIST |
lists.debian.org |
|
| RCE in H2 Console · Advisory · h2database/h2database · GitHub |
MISC |
github.com |
|
| Log4Shell-Critical Remote Code Execution Vulnerability in H2database Console - SecPod Blog |
MISC |
www.secpod.com |
|
| CVE-2021-42392 H2 Database Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| JNDI-Related Vulnerability Discovered in H2 Database Console |
MISC |
jfrog.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179074 Debian Security Update for h2database (DLA 2923-1)
- 179077 Debian Security Update for h2database (DSA 5076-1)
- 184835 Debian Security Update for h2database (CVE-2021-42392)
- 198730 Ubuntu Security Notification for H2 Vulnerabilities (USN-5365-1)
- 240458 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 7 (RHSA-2022:4918)
- 240459 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 8 (RHSA-2022:4919)
- 376244 H2 Database Console Remote Code Execution (RCE) Vulnerability (CVE-2021-42392)