Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1963
Reference (s):
- https://lists.apache.org/thread.html/r1933faf8a26c431f38a5f8dbbfab80254454e54e33a79be474b67dc4%40%3Cdev.ignite.apache.org%3E
- URL: https://lists.apache.org/thread.html/r1933faf8a26c431f38a5f8dbbfab80254454e54e33a79be474b67dc4%40%3Cdev.ignite.apache.org%3E
- https://www.oracle.com/security-alerts/cpujan2022.html
- URL: https://www.oracle.com/security-alerts/cpujan2022.html
- MLIST:[ignite-dev] 20200603 RE: [CVE-2020-1963] Apache Ignite access to file system disclosure vulnerability

