CVE-2018-10054
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 34%
from disclosure to weapon0 days
Published on NVDApr 11
metasploitApr 9
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
Affected products
n/a · n/aReferences
http://blog.datomic.com/2018/03/important-security-update.htmlhttps://forum.datomic.com/t/important-security-update-0-9-5697/379https://github.com/h2database/h2database/issues/1225https://github.com/h2database/h2database/issues/1808#issuecomment-599203115https://github.com/h2database/h2database/issues/3099https://lists.apache.org/thread.html/582d4165de6507b0be82d5a6f9a1ce392ec43a00c9fed32bacf7fe1e%40%3Cuser.ignite.apache.org%3Ehttps://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3Ehttps://mthbernardes.github.io/rce/2018/03/14/abusing-h2-database-alias.htmlhttps://security.netapp.com/advisory/ntap-20240719-0003/https://www.exploit-db.com/exploits/44422/