• 公告ID (KylinSec-SA-2022-1080)

摘要:

The package com.h2database:h2 from 0 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

安全等级: Low

公告ID: KylinSec-SA-2022-1080

发布日期: 2022年9月29日

关联CVE: CVE-2021-23463  

  • 详细介绍

1. 漏洞描述

   

The package com.h2database:h2 from 0 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-23463 KY3.4-4A h2 Unaffected
CVE-2021-23463 KY3.4-5A h2 Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-1079 下一篇:KylinSec-SA-2022-1081