CVE-2022-23221: Critical severity h2database H2 vulnerability
A flaw was found in the H2 Console. This flaw allows remote attackers to execute arbitrary code via a JDBC URL, concatenating with a substring that allows remote code execution by using a script.
Other sources
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNOREUNKNOWNSETTINGS=TRUE;FORBIDCREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.h2database:h2to a version that resolves this vulnerability.Fixed in 2.1.210 - Upgrade
Upgrade
redhat/eap7-h2databaseto a version that resolves this vulnerability.Fixed in 0:1.4.197-2.redhat_00004.1.el8ea - Upgrade
Upgrade
redhat/eap7-h2databaseto a version that resolves this vulnerability.Fixed in 0:1.4.197-2.redhat_00004.1.el7ea - Upgrade
Upgrade
debian/h2databaseto a version that resolves this vulnerability.Fixed in 1.4.197-4+deb10u1Fixed in 1.4.197-4+deb11u1Fixed in 2.1.214-1Fixed in 2.2.220-1 - Upgrade
Upgrade
redhat/h2to a version that resolves this vulnerability.Fixed in 2.1.210 - Upgrade
Upgrade
h2database/h2database (H2 Console)to a version that resolves this vulnerability.Fixed in 2.1.210 - Compensating control
Prevent remote access to the H2 Console until updated to a version that is not "before 2.1.210" (e.g., restrict network/firewall access to the Console endpoint).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-23221?
CVE-2022-23221 is a vulnerability in H2 Console that allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL.
How severe is CVE-2022-23221?
CVE-2022-23221 is considered critical with a severity score of 9.8.
How can an attacker exploit CVE-2022-23221?
An attacker can exploit CVE-2022-23221 by using a specially crafted JDBC URL to execute arbitrary code remotely.
Which software versions are affected by CVE-2022-23221?
EAP7 H2 Database versions 0:1.4.197-2.redhat_00004.1.el8ea and 0:1.4.197-2.redhat_00004.1.el7ea are affected, as well as H2 Database version up to 2.0.206 and H2 versions up to 2.1.210.
How do I mitigate the CVE-2022-23221 vulnerability?
To mitigate the CVE-2022-23221 vulnerability, update to H2 Console version 2.1.210 or later.