VulnerabilityModified
CVE-2018-10054
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.
HIGH 8.8EPSS 33.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 33.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 33.93% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cognitect/datomic · h2database/h2
- Source
- cve@mitre.org
References
- http://blog.datomic.com/2018/03/important-security-update.htmlVendor Advisory
- https://forum.datomic.com/t/important-security-update-0-9-5697/379Vendor Advisory
- https://github.com/h2database/h2database/issues/1225
- https://github.com/h2database/h2database/issues/1808#issuecomment-599203115
- https://github.com/h2database/h2database/issues/3099
- https://lists.apache.org/thread.html/582d4165de6507b0be82d5a6f9a1ce392ec43a00c9fed32bacf7fe1e%40%3Cuser.ignite.apache.org%3E
- https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E
- https://mthbernardes.github.io/rce/2018/03/14/abusing-h2-database-alias.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20240719-0003/
- https://www.exploit-db.com/exploits/44422/Third Party Advisory, VDB Entry
- http://blog.datomic.com/2018/03/important-security-update.htmlVendor Advisory
- https://forum.datomic.com/t/important-security-update-0-9-5697/379Vendor Advisory
- https://github.com/h2database/h2database/issues/1225
- https://github.com/h2database/h2database/issues/1808#issuecomment-599203115
- https://github.com/h2database/h2database/issues/3099
- https://lists.apache.org/thread.html/582d4165de6507b0be82d5a6f9a1ce392ec43a00c9fed32bacf7fe1e%40%3Cuser.ignite.apache.org%3E
- https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3E
- https://mthbernardes.github.io/rce/2018/03/14/abusing-h2-database-alias.htmlThird Party Advisory
- https://security.netapp.com/advisory/ntap-20240719-0003/
- https://www.exploit-db.com/exploits/44422/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.