亚洲狼友综合在线导航|国产在线拍揄自揄拍无码男男|跪求一个免费的黄色在线网址|国产r级片在线观看完整版视频|国产欧美亚洲日本视频|视频成人一二区啊轻点插|免费观看!毛片久热久|欧美成人高清导航|无码高清色情97视频在线|精品黄色成人网站在线观看

Service Notices

All Notices > Security Notices > HyperSQL Database (HSQLDB) Remote Code Execution Vulnerability (CVE-2022-41853)

HyperSQL Database (HSQLDB) Remote Code Execution Vulnerability (CVE-2022-41853)

Oct 27, 2022 GMT+08:00

I. Overview

Recently, it has been disclosed that there is an important remote code execution vulnerability (CVE-2022-41853) in the HyperSQL database. By default, HyperSQL SQL statements can invoke any static method from any Java class in the class path. When java.sql.Statement and java.sql.PreparedStatement are used to parse untrusted binary or text data, remote code execution may occur.

HSQLDB is an open-source relational database written in Java. If you are an HSQLDB user, check your HSQLDB version and implement timely security hardening.

Reference:

https://www.code-intelligence.com/blog/potential-remote-code-execution-in-hsqldb

II. Severity

Severity: important

(Severity: low, moderate, important, and critical)

III. Affected Products

Affected versions:

HSQLDB < 2.7.1

Secure versions:

HSQLDB 2.7.1

IV. Vulnerability Handling

This vulnerability has been fixed in version 2.7.1. If your service version is earlier than 2.7.1, upgrade it to version 2.7.1.

http://hsqldb.org/

Note: Before fixing vulnerabilities, back up your files and conduct a thorough test.