
CVE-2021-42392
- Reference to the description:
- Description:
- The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
- Last updated date:
- 02/24/2023
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 01/09/2022
- Reference url to background
https://github.com/cybersecurityworks553/CVE-2021-42392-Detect
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 01/19/2022
- Reference url to background
https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/