CVE-2018-10054

HIGH

H2 1.4.197 - RCE

Title source: llm

Description

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."

Exploits (2)

exploitdb WORKING POC VERIFIED
by gambler · pythonlocaljava
https://www.exploit-db.com/exploits/44422
metasploit WORKING POC EXCELLENT
by h00die, gambler, h4ckNinja, Nairuz Abulhul · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/h2_webinterface_rce.rb

Scores

CVSS v3 8.8
EPSS 0.7158
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (3)
cognitect/datomic < 0.9.5697
com.datomic/datomic-free 0 - 0.9.5697Maven
h2database/h2 1.4.197
Published Apr 11, 2018
Tracked Since Feb 18, 2026