CVE-2018-10054

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
11/04/2018
Last modified:
05/08/2024

Description

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cognitect:datomic:*:*:*:*:*:*:*:* 0.9.5697 (excluding)
cpe:2.3:a:h2database:h2:1.4.197:*:*:*:*:*:*:*