Red Hat Bugzilla – Bug 1610877
CVE-2018-14335 h2: Information Exposure due to insecure handling of permissions in the backup
Last modified: 2018-10-19 17:52:48 EDT
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file. References: https://gist.github.com/owodelta/9714faf9a86435cef5a99d4930eaee20
Created h2 tracking bugs for this issue: Affects: fedora-all [bug 1610878]