High severity8.8NVD Advisory· Published Apr 11, 2018· Updated Jun 17, 2026
CVE-2018-10054
CVE-2018-10054
Description
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.datomic:datomic-freeMaven | < 0.9.5697 | 0.9.5697 |
Affected products
1Patches
Vulnerability mechanics
References
16- blog.datomic.com/2018/03/important-security-update.htmlnvdVendor AdvisoryWEB
- forum.datomic.com/t/important-security-update-0-9-5697/379nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-9pf8-qqhm-7w64ghsaADVISORY
- mthbernardes.github.io/rce/2018/03/14/abusing-h2-database-alias.htmlnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-10054ghsaADVISORY
- www.exploit-db.com/exploits/44422/nvdThird Party AdvisoryVDB Entry
- github.com/h2database/h2database/issues/1225nvdWEB
- github.com/h2database/h2database/issues/1808nvdWEB
- github.com/h2database/h2database/issues/3099nvdWEB
- lists.apache.org/thread.html/582d4165de6507b0be82d5a6f9a1ce392ec43a00c9fed32bacf7fe1e%40%3Cuser.ignite.apache.org%3EnvdWEB
- lists.apache.org/thread.html/582d4165de6507b0be82d5a6f9a1ce392ec43a00c9fed32bacf7fe1e@%3Cuser.ignite.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540%40%3Ccommits.nifi.apache.org%3EnvdWEB
- lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540@%3Ccommits.nifi.apache.org%3EghsaWEB
- security.netapp.com/advisory/ntap-20240719-0003ghsaWEB
- www.exploit-db.com/exploits/44422ghsaWEB
- security.netapp.com/advisory/ntap-20240719-0003/nvd
News mentions
0No linked articles in our index yet.