Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Synk reports vulnerability for h2 dependency #51

Open
KilianB opened this issue Jun 20, 2021 · 0 comments
Open

Synk reports vulnerability for h2 dependency #51

KilianB opened this issue Jun 20, 2021 · 0 comments
Labels

Comments

@KilianB
Copy link
Owner

KilianB commented Jun 20, 2021

According to Synk a critical vulnerability for h2 exists: https://snyk.io/vuln/SNYK-JAVA-COMH2DATABASE-31685?utm_medium=Partner&utm_source=RedHat&utm_campaign=Code-Ready-Analytics-2020&utm_content=vuln/SNYK-JAVA-COMH2DATABASE-31685

Please see the issue ticket in the original repository here as well as the developers comment: h2database/h2database#3012

TLDR: The default configuration prevents a RCE, the library is not used in such a capability in JImage hash and is only an optional dependency. No patch version from h2 is and will be made available. The report is a false positive and can be ignored if you do not manually open up the h2 to the web and alter the settings manually.

@KilianB KilianB added the Notice label Jun 20, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant