CVE-2021-42392
h2database - security update
9.8
CRITICAL
CVSS 3.1
EPSS 90.6%
Description
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
How to fix CVE-2021-42392
To remediate CVE-2021-42392, upgrade the affected package to a fixed version below.
- —upgrade to 1.4.197-4+deb11u1 or later
- —upgrade to 1.4.193-1+deb9u1 or later
- —upgrade to 1.4.197-4+deb10u1 or later
- —upgrade to 2.0.206 or later
Is CVE-2021-42392 being exploited?
Likely — EPSS is 90.6%, placing CVE-2021-42392 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (4)
- from 0, < 1.4.197-4+deb11u1
- from 0, < 1.4.193-1+deb9u1
- from 0, < 1.4.197-4+deb10u1
- >= 1.1.100, < 2.0.206
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |