OP 08 January, 2022 - 08:38 AM
Quote:Researchers have disclosed a security flaw affecting H2 database consoles that could result in remote code execution. The flaw echoes the Log4j "Log4Shell" vulnerability that came to light last month. H2 is an open-source relational database management system written in Java that can be embedded within applications or run in client-server mode. The issue, tracked as CVE-2021-42392, is the first critical issue published since Log4Shell, that exploits the same root cause of the vulnerability.
Source: https://thehackernews.com/2022/01/log4sh...w.html?m=1