-
Type: Bug
-
Status: Resolved
-
Priority: Major
-
Resolution: Fixed
-
Affects Version/s: 2023.7
-
Fix Version/s: 2023.9
-
Component/s: Distribution / Installers
-
Release Notes Summary:The H2 embeddable database was upgraded from 2.1.214 to 2.2.224.
-
Tags:
-
Backlog priority:800
-
Upgrade notes:
-
Sprint:nxplatform #108
-
Story Points:2
Client reported vulnerability flagged by Prisma scan below,
Nuxeo is not affected in anyway by this vulnerability but upgrade is done to comply with security scans.
The web-based admin console in H2 Database Engine through 2.1.214 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states \"This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that.\"