CVE-2018-10054
11.04.2018, 20:29
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."Enginsight
Vendor | Product | Version |
---|---|---|
cognitect | datomic | 𝑥 < 0.9.5697 |
h2database | h2 | 1.4.197 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References