CVE-2021-23463

EUVD-2021-2477
The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
snykCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H/E:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Affected Products (NVD)
VendorProductVersion
h2databaseh2
1.4.198 ≤
𝑥
< 2.0.202
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
h2database
bookworm
2.1.214-1
fixed
bullseye
1.4.197-4+deb11u1
fixed
bullseye (security)
1.4.197-4+deb11u1
fixed
sid
2.2.220-1
fixed
trixie
2.2.220-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
h2database
bionic
not-affected
focal
not-affected
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
ignored
lunar
ignored
mantic
not-affected
noble
not-affected
trusty
ignored
xenial
not-affected