VYPR

Maven package

com.datomic/datomic-free

pkg:maven/com.datomic/datomic-free

Vulnerabilities (1)

  • CVE-2018-10054Apr 11, 2018
    affected < 0.9.5697fixed 0.9.5697

    H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."