REDHAT-BUG-1610877: Medium severity H2 H2 Database Engine vulnerability
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
References: https://gist.github.com/owodelta/9714faf9a86435cef5a99d4930eaee20
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1610877?
The severity of REDHAT-BUG-1610877 is high due to the potential for attackers to read sensitive files.
How do I fix REDHAT-BUG-1610877?
To fix REDHAT-BUG-1610877, upgrade to a patched version of H2 that addresses the insecure handling of permissions.
What vulnerable version of H2 is identified in REDHAT-BUG-1610877?
H2 version 1.4.197 is identified as vulnerable in REDHAT-BUG-1610877.
What type of attacks are possible due to REDHAT-BUG-1610877?
Insecure handling of permissions in REDHAT-BUG-1610877 allows attackers to read files outside their permissions, enabling data leakage.
Which software is affected by REDHAT-BUG-1610877?
The affected software in REDHAT-BUG-1610877 is the H2 Database Engine.