← Back to CVE List

CVE-2021-42392

Published: 2022-01-10T14:10Z
Last Modified: 2024-11-21T06:27Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt