CVE-2021-23463 (High) Detected In H2-1.4.199.jar, H2-1.4.200.jar ...
- Notifications You must be signed in to change notification settings
- Fork 1.3k
- Star 2k
- Code
- Issues 919
- Pull requests 232
- Actions
- Projects 0
- Wiki
- Security
- Insights
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
Sign up for GitHubBy clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Jump to bottom CVE-2021-23463 (High) detected in h2-1.4.199.jar, h2-1.4.200.jar - autoclosed #3253 Closed mend-bolt-for-github bot opened this issue Dec 17, 2021 · 1 comment Closed CVE-2021-23463 (High) detected in h2-1.4.199.jar, h2-1.4.200.jar - autoclosed #3253 mend-bolt-for-github bot opened this issue Dec 17, 2021 · 1 comment Labels Mend: dependency security vulnerability Security vulnerability detected by WhiteSourceComments
Copy link Contributormend-bolt-for-github bot commented Dec 17, 2021 • edited Loading
CVE-2021-23463 - High Severity VulnerabilityVulnerable Libraries - h2-1.4.199.jar, h2-1.4.200.jar h2-1.4.199.jarH2 Database Engine Library home page: http://www.h2database.com Path to dependency file: /hapi-fhir-jpaserver-test-utilities/pom.xml Path to vulnerable library: /repository/com/h2database/h2/1.4.199/h2-1.4.199.jar Dependency Hierarchy:
H2 Database Engine Library home page: https://h2database.com Path to dependency file: /hapi-fhir-cli/hapi-fhir-cli-app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/h2database/h2/1.4.200/h2-1.4.200.jar Dependency Hierarchy:
Found in base branch: master Vulnerability DetailsThe package com.h2database:h2 from 0 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability. Publish Date: 2021-12-10 URL: CVE-2021-23463 CVSS 3 Score Details (9.1)Base Score Metrics:
Type: Upgrade version Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-23463 Release Date: 2021-12-10 Fix Resolution: com.h2database:h2:2.0.202 Step up your Open Source Security Game with WhiteSource here |
The text was updated successfully, but these errors were encountered: |
mend-bolt-for-github bot commented Jan 4, 2022
✔️ This issue was automatically closed by WhiteSource because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the WhiteSource inventory. |
Sorry, something went wrong.
mend-bolt-for-github bot closed this as completed Jan 4, 2022 Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment Assignees No one assigned Labels Mend: dependency security vulnerability Security vulnerability detected by WhiteSource Projects None yet Milestone No milestone DevelopmentNo branches or pull requests
0 participants You can’t perform that action at this time.Từ khóa » H2 1.4.200 Cve
-
H2database H2 : List Of Security Vulnerabilities - CVE Details
-
Com.h2database:h2@1.4.200 Vulnerabilities - Snyk
-
Com.h2database:h2 Vulnerabilities - Snyk
-
National Vulnerability Database - NVD - Results
-
Is The Latest H2 (1.4.200) Database Still Have Security Vulnerabilities
-
Vulnerability In Com.h2database:h2@1.4.200 · Issue #3339 - GitHub
-
JNDI-Related Vulnerability Discovered In H2 Database Console
-
Is The Latest H2 (1.4.200) Database Still Have Security Vulnerabilities
-
Information Disclosure Vulnerability In The H2 Database Engine Library
-
CVE-2021-23463 - XXE Vulnerability In H2Database H2 1.4.198/1.4 ...
-
CVE - Search Results - The MITRE Corporation
-
[#IGNITE-15241] Ignite H2 Security Vulnerabilities - ASF JIRA
-
Dependency-Check Report - Free Dumb Bytes
-
Dependency-Check Report - GitHub Pages