CVE-2021-42392 : The JNDI Strikes Back – Unauthenticated RCE in H2 Database Console. H2 is a very popular open-source Java SQL database. Notes: newer versions of Java contain the trustURLCodebase
mitigation that will not allow remote codebases to be loaded naively via JNDI. However, this mitigation is not bulletproof.. #vuln #software #java #storage #sql #database #cyber #threats #informatique
https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/