CVE-2018-10054: Input Validation
Published Apr 11, 2018
·Updated
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.
Affected Software
3 affected componentsFixes available
maven/com.datomic:datomic-free<=0.9.5656
0.9.5697
Cognitect Datomic<0.9.5697
h2database H2=1.4.197
Event History
Apr 11, 2018
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
May 13, 2022
Advisory Published
01:30 AM
Frequently Asked Questions
1
What is CVE-2018-10054?
CVE-2018-10054 is a vulnerability in H2 1.4.197 that allows remote code execution.
2
Which products are affected by CVE-2018-10054?
Cognitect Datomic before version 0.9.5697 and H2database H2 version 1.4.197 are affected by CVE-2018-10054.
3
How severe is CVE-2018-10054?
CVE-2018-10054 has a severity score of 8.8, which is considered high.
4
How can remote code execution be achieved with CVE-2018-10054?
Remote code execution can be achieved with CVE-2018-10054 through the use of CREATE ALIAS, which can execute arbitrary Java code.
5
Is there a fix available for CVE-2018-10054?
Yes, upgrading to Datomic version 0.9.5697 or higher and H2database H2 version 1.4.198 or higher fixes CVE-2018-10054.