VYPR
High severity8.8NVD Advisory· Published Apr 11, 2018· Updated Jun 17, 2026

CVE-2018-10054

CVE-2018-10054

Description

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.datomic:datomic-freeMaven
< 0.9.56970.9.5697

Affected products

1

Patches

Vulnerability mechanics

References

16

News mentions

0

No linked articles in our index yet.