First published: Wed Apr 11 2018(Updated: )
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cognitect Datomic | <0.9.5697 | |
H2database H2 | =1.4.197 | |
maven/com.datomic:datomic-free | <=0.9.5656 | 0.9.5697 |
<0.9.5697 | ||
=1.4.197 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10054 is a vulnerability in H2 1.4.197 that allows remote code execution.
Cognitect Datomic before version 0.9.5697 and H2database H2 version 1.4.197 are affected by CVE-2018-10054.
CVE-2018-10054 has a severity score of 8.8, which is considered high.
Remote code execution can be achieved with CVE-2018-10054 through the use of CREATE ALIAS, which can execute arbitrary Java code.
Yes, upgrading to Datomic version 0.9.5697 or higher and H2database H2 version 1.4.198 or higher fixes CVE-2018-10054.