PT-2022-7166 · Unknown+1 · H2 Database Engine+1
Legolasbo
+3
·
Published
2022-11-23
·
Updated
2024-08-03
·
CVE-2022-45868
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
H2 Database Engine versions prior to 2.2.220
Description
The web-based admin console in H2 Database Engine can be started via the CLI with the argument
-webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. The issue was fixed in version 2.2.220.Recommendations
For H2 Database Engine versions prior to 2.2.220, update to version 2.2.220 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the
-webAdminPassword argument when starting the web-based admin console via the CLI to minimize the risk of password exposure.Exploit
Fix
Information Disclosure
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
H2 Database Engine