CVE-2018-10054

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cognitect:datomic:*:*:*:*:*:*:*:*
cpe:2.3:a:h2database:h2:1.4.197:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-04-11 20:29

Updated : 2024-07-19 14:15


NVD link : CVE-2018-10054

Mitre link : CVE-2018-10054

CVE.ORG link : CVE-2018-10054


JSON object : View

Products Affected

cognitect

  • datomic

h2database

  • h2
CWE
CWE-20

Improper Input Validation