GHSA-22wj-vf5f-wrvj

    Dashboard / Vulnerabilities / GHSA-22wj-vf5f-wrvj

    GHSA-22wj-vf5f-wrvj

    Published: 23 Nov 2022Last Modified: 10 Sept 2026

    Summary: Password exposure in H2 Database

    Details: The web-based admin console in H2 Database Engine through 2.1.214 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states "This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that."

    Affected packages

    Package

    Name: com.h2database:h2

    Purl: pkg:maven/com.h2database/h2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.4.198
    Fixed -2.2.220

    Affected versions

    1.4.198
    1.4.199
    1.4.200

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-22wj-vf5f-wrvj | CVE-DB