UBUNTU-CVE-2021-42392
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-42392
UBUNTU-CVE-2021-42392
Summary:
Details: The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
References: https://ubuntu.com/security/CVE-2021-42392, https://github.com/h2database/h2database/security/advisories/GHSA-h376-j262-vhq6, https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/, https://ubuntu.com/security/notices/USN-5365-1, https://www.cve.org/CVERecord?id=CVE-2021-42392, https://ubuntu.com/security/notices/USN-6834-1
Affected packages
Package
Name: h2database
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
