Improper Input Validation in Datomic
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jul 19, 2024
Description
Published by the National Vulnerability Database
Apr 11, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 30, 2022
Last updated
Jul 19, 2024
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.
References