CVE-2021-23463 is an XML External Entity (XXE) Injection vulnerability affecting the H2 database, specifically versions 1.4.198 up to, but not including, 2.0.202. This critical vulnerability (CVSS 9.1) allows an unauthenticated attacker to remotely inject malicious XML, potentially leading to information disclosure or denial of service. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's minimal community discussion or media coverage, the high CVSS score indicates a significant risk if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.198, < 2.0.202CPE matchmatch criteria | cpe:2.3:a:h2database:h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.