UBUNTU-CVE-2022-23221
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-23221
UBUNTU-CVE-2022-23221
Summary:
Details: H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
References: https://ubuntu.com/security/CVE-2022-23221, https://github.com/h2database/h2database/security/advisories, https://github.com/h2database/h2database/releases/tag/version-2.1.210, https://twitter.com/d0nkey_man/status/1483824727936450564, https://ubuntu.com/security/notices/USN-5365-1, https://www.cve.org/CVERecord?id=CVE-2022-23221, https://ubuntu.com/security/notices/USN-6834-1
Affected packages
Package
Name: h2database
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
