An issue was discovered in H2 1.4.197. Insecure handling...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 29, 2024
Description
Published by the National Vulnerability Database
Jul 24, 2018
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Oct 29, 2024
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
References