Your agents are only as trustworthy as what they consume, build, and ship. JFrog governs every AI model, agent skill, MCP server, AI-generated code, and assembled artifact in a single source of truth.
Secure your entire agentic software supply chain so you can ship trusted software at your new speed.
The JNDI Strikes Back – Unauthenticated RCE in H2 Database Console
Update 07/01/22 – Added credit to researcher @pyn3rd for similar independent previous findings in Acknowledgements section Update 4/30/26 – Since this post was published, a second critical RCE vulnerability was discovered in H2 Console: CVE-2022-23221 (CVSS 9.8), which exploits malicious JDBC URLs. It was fixed in H2 version 2.1.210. We recommend upgrading to the latest … Continue reading The JNDI Strikes Back – Unauthenticated RCE in H2 Database Console
Copy and paste this URL into your WordPress site to embed
Copy and paste this code into your site to embed
Your submission has been recieved.
We will contact you soon!
Please try again later
Modal Message