CVE-2021-42392: Critical severity h2database H2 vulnerability
A flaw was found in h2. The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. This flaw allows an attacker to use this URL to send another server’s code, causing remote code execution. This issue is exploited through various attack vectors, most notably through the H2 Console, which leads to unauthenticated remote code execution.
Other sources
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/eap7-h2databaseto a version that resolves this vulnerability.Fixed in 0:1.4.197-2.redhat_00004.1.el8ea - Upgrade
Upgrade
redhat/eap7-h2databaseto a version that resolves this vulnerability.Fixed in 0:1.4.197-2.redhat_00004.1.el7ea - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:15.0.8-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:15.0.8-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el8 - Upgrade
Upgrade
redhat/rh-sso7to a version that resolves this vulnerability.Fixed in 0:1-5.el9 - Upgrade
Upgrade
redhat/rh-sso7-javapackages-toolsto a version that resolves this vulnerability.Fixed in 0:6.0.0-7.el9 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:18.0.3-1.redhat_00001.1.el9 - Upgrade
Upgrade
debian/h2databaseto a version that resolves this vulnerability.Fixed in 1.4.197-4+deb10u1Fixed in 1.4.197-4+deb11u1Fixed in 2.1.214-1Fixed in 2.2.220-1 - Upgrade
Upgrade
redhat/h2to a version that resolves this vulnerability.Fixed in 2.0.206
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-42392?
CVE-2021-42392 is a vulnerability found in the h2 database that allows remote code execution.
How severe is CVE-2021-42392?
CVE-2021-42392 has a severity rating of 9.8, which is considered critical.
How can I fix CVE-2021-42392?
To fix CVE-2021-42392, you should update the h2 database to version 2.0.206 or apply the recommended patch provided by Red Hat.
Where can I find more information about CVE-2021-42392?
You can find more information about CVE-2021-42392 on the GitHub security advisory page and the Red Hat security advisory page.
What is the Common Weakness Enumeration (CWE) for CVE-2021-42392?
The Common Weakness Enumeration (CWE) for CVE-2021-42392 is CWE-502.