In response to recently announced vulnerabilities related to H2DB (CVE-2022-23221; CVE-2021-42392l; CVE-2021-23463), we are upgrading the H2DB from version 1.4.194 to the most secure version 2.1.210.
As a result of this upgrade, a new runtime with new jar files will be available for installation.
Customers will need to do the following:
- Upgrade to the new runtime version
- All G-Repositories will need to be deleted and recreated
- Any H2 databases created by GenRocket Runtime in the .genrocket folder will need to be deleted (example of H2 databases - gen_rocket_state.mv.db; EDI.mv.db, etc.)
- Any custom databases whose data is being populated by the H2InsertV2Receiver will also need to be deleted and recreated.