CVE-2018-10054
HIGHH2 1.4.197 - RCE
Title source: llmDescription
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by gambler · pythonlocaljava
https://www.exploit-db.com/exploits/44422
metasploit
WORKING POC
EXCELLENT
by h00die, gambler, h4ckNinja, Nairuz Abulhul · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/h2_webinterface_rce.rb
References (10)
Scores
CVSS v3
8.8
EPSS
0.7158
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (3)
cognitect/datomic
< 0.9.5697
com.datomic/datomic-free
0 - 0.9.5697Maven
h2database/h2
1.4.197
Published
Apr 11, 2018
Tracked Since
Feb 18, 2026