https://nvd.nist.gov/vuln/detail/CVE-2022-45868
Total waste of everybody's time. You have to start h2 as server, instead of as dependency. You then have to start it with a command line parameter with a password, instead of specifying it in a config file. Both actions scream debug-configuration. If you do this, then... the password is readable on the command line.
That's the whole vulnerability. Analogy: if you leave a key on the table, people inside the same house can take it, and that's a vulnerability for the door.
So now h2 is 'vulnerable', every application needs to upgrade the dependency, and everybody needs to upgrade the application. What a total waste of time.