CVE-2021-42392

CVE-2021-42392

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

Source: CVE-2021-42392

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다