Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2vc-m5fv-9w9m

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

H2O Vulnerable to Denial of Service (DoS) via /3/ImportFiles Endpoint

A vulnerability in the /3/ImportFiles endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, path, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.

Пакеты

Наименование

h2o

pip
Затронутые версииВерсия исправления

<= 3.46.1

Отсутствует

Наименование

ai.h2o:h2o-core

maven
Затронутые версииВерсия исправления

<= 3.46.1

Отсутствует

EPSS

Процентиль: 34%
0.00137
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.

EPSS

Процентиль: 34%
0.00137
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-770