[#IGNITE-15241] Ignite H2 Security Vulnerabilities - ASF JIRA
Public signup for this instance is disabled. Go to our Self serve sign up page to request an account. Report potential security issues privately
Details
- Type: Bug
- Status: Closed
- Priority: Major
- Resolution: Won't Fix
- Affects Version/s: 2.13
- Fix Version/s: None
- Component/s: sql
- Labels:
- cggg
Description
Upgrade H2 dependency of the ignite-indexing module to the latest version 1.4.200.
Apache Ignite SQL (module ignite-indexing) depends on H2 database version 1.4.197. Black Duck SCA detects these security vulnerabilities in H2:
We did preliminary real impact analysis considering how Ignite uses H2:
- CVE-2018-14335 This vulnerability is not applicable to H2 in Ignite since Ignite does not store data in H2 and thus there can be no H2 backups in Ignite.
- CVE-2018-10054 This vulnerability is not applicable to H2 in Ignite since Ignite does not support the CREATE ALIAS statement
- CVE-2021-23463 This vulnerability is not applicable to H2 in Ignite since Ignite uses H2 version 1.4.197 and the vulnerability is applicable to H2 version 1.4.198 and up to 2.0.202.
- CVE-2022-23221 This vulnerability is not applicable to H2 in Ignite since Ignite runs H2 in embedded mode. H2 cannot be externally exposed in embedded mode. The vulnerability could be exploited on the local machine where Ignite is running. However, this limits the severity a lot.
- CVE-2021-42392 This vulnerability is not applicable to H2 in Ignite since Ignite does not use and does not expose the org.h2.util.JdbcUtils.getConnection method.
We realize all those vulnerabilities are not applicable to H2 in Apache Ignite. However, our security policies are very formal and require somehow addressing the security vulnerabilities anyway.
We believe there are lots of other enterprises having the same issue. For example, there is another issue IGNITE-14381 referencing the same problem.
Attachments
Attachments
- Options
- Sort By Name
- Sort By Date
- Ascending
- Descending
- Ignite-H2-Vulnerabilities.png27/May/22 08:4433 kBAlexey Kukushkin
Issue Links
fixesIGNITE-14381 Failed to initialize DB connection- Unsupported connection setting "MULTI_THREADED"
- Open
IGNITE-16384 H2 database used in Ignite has high security vulnerabilities
- Resolved
Activity
People
Assignee: Alexey Kukushkin Reporter: Alexey Kukushkin Votes: 1 Vote for this issue Watchers: 6 Start watching this issueDates
Created: 03/Aug/21 19:12 Updated: 25/Sep/22 14:48 Resolved: 27/May/22 16:08Time Tracking
Estimated:Từ khóa » H2 1.4.200 Cve
-
H2database H2 : List Of Security Vulnerabilities - CVE Details
-
Com.h2database:h2@1.4.200 Vulnerabilities - Snyk
-
Com.h2database:h2 Vulnerabilities - Snyk
-
National Vulnerability Database - NVD - Results
-
Is The Latest H2 (1.4.200) Database Still Have Security Vulnerabilities
-
Vulnerability In Com.h2database:h2@1.4.200 · Issue #3339 - GitHub
-
CVE-2021-23463 (High) Detected In H2-1.4.199.jar, H2-1.4.200.jar ...
-
JNDI-Related Vulnerability Discovered In H2 Database Console
-
Is The Latest H2 (1.4.200) Database Still Have Security Vulnerabilities
-
Information Disclosure Vulnerability In The H2 Database Engine Library
-
CVE-2021-23463 - XXE Vulnerability In H2Database H2 1.4.198/1.4 ...
-
CVE - Search Results - The MITRE Corporation
-
Dependency-Check Report - Free Dumb Bytes
-
Dependency-Check Report - GitHub Pages