First published: Mon Jul 23 2018(Updated: )
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
H2database H2 | =1.4.197 | |
=1.4.197 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-14335 is medium with a CVSS score of 6.5.
CVE-2018-14335 is an issue in H2 1.4.197 where insecure handling of permissions in the backup function allows attackers to read sensitive files via a symlink to a fake database file.
CVE-2018-14335 affects H2database H2 version 1.4.197 by allowing attackers to read sensitive files outside of their permissions.
Yes, you can find references for CVE-2018-14335 at the following links: [Link 1](https://gist.github.com/owodelta/9714faf9a86435cef5a99d4930eaee20), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1610878), [Link 3](https://access.redhat.com/support/policy/updates/jboss_notes).
CVE-2018-14335 belongs to CWE-200 and CWE-59.