SCA: security update for com.h2database:h2 (GHSA-22wj-vf5f-wrvj)

high Tenable Self-Hosted Container Security Plugin ID 421769

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the
argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin
console. Consequently, a local user (or an attacker that has obtained local access through some means)
would be able to discover the password by listing processes and their arguments. NOTE: the vendor states
"This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and
every qualified DBA or system administrator is expected to know that." Nonetheless, the issue was fixed in
2.2.220. (CVE-2022-45868)

See Also

https://github.com/advisories/GHSA-22wj-vf5f-wrvj

Plugin Details

Severity: High

ID: 421769

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 3/28/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.86

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2022-45868

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/23/2022

Vulnerability Publication Date: 11/23/2022

Reference Information

CVE: CVE-2022-45868