CVE-2021-23463

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
snykCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H/E:P
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
h2databaseh2
1.4.198 ≤
𝑥
< 2.0.202
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
h2database
bullseye (security)
1.4.197-4+deb11u1
fixed
bullseye
1.4.197-4+deb11u1
fixed
bookworm
2.1.214-1
fixed
sid
2.2.220-1
fixed
trixie
2.2.220-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
h2database
noble
not-affected
mantic
not-affected
lunar
ignored
kinetic
ignored
jammy
not-affected
impish
ignored
hirsute
ignored
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
ignored