CVE-2022-23221
Summary
| CVE | CVE-2022-23221 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-19 17:15:00 UTC |
| Updated | 2023-08-18 14:15:00 UTC |
| Description | H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5076-1 h2database |
DEBIAN |
www.debian.org |
|
| Release Version 2.1.210 · h2database/h2database · GitHub |
CONFIRM |
github.com |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| CVE-2022-23221 H2 Database Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [SECURITY] [DLA 2923-1] h2database security update |
MLIST |
lists.debian.org |
|
| JavaScript is not available. |
MISC |
twitter.com |
|
| Security Advisories · h2database/h2database · GitHub |
MISC |
github.com |
|
| Full Disclosure: Unauthenticated RCE vuln in the H2 Database console: CVE-2022-23221. |
FULLDISC |
seclists.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| H2 Database Console Remote Code Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179074 Debian Security Update for h2database (DLA 2923-1)
- 179077 Debian Security Update for h2database (DSA 5076-1)
- 182487 Debian Security Update for h2database (CVE-2022-23221)
- 198730 Ubuntu Security Notification for H2 Vulnerabilities (USN-5365-1)
- 240458 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 7 (RHSA-2022:4918)
- 240459 Red Hat Update for JBoss Enterprise Application Platform 7.4.5 on RHEL 8 (RHSA-2022:4919)