Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w36w-948j-xhfw

Опубликовано: 21 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

H2O vulnerable to Deserialization of Untrusted Data

The H2O machine learning platform uses "Iced" classes as the primary means of moving Java Objects around the cluster. The Iced format supports inclusion of serialized Java objects. When a model is deserialized, any class is allowed to be deserialized (no class whitelist). An attacker can construct a crafted Iced model that uses Java gadgets and leads to arbitrary code execution when imported to the H2O platform.

Пакеты

Наименование

ai.h2o:h2o-core

maven
Затронутые версииВерсия исправления

<= 3.46.0.4

Отсутствует

EPSS

Процентиль: 47%
0.00241
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

The H2O machine learning platform uses "Iced" classes as the primary means of moving Java Objects around the cluster. The Iced format supports inclusion of serialized Java objects. When a model is deserialized, any class is allowed to be deserialized (no class whitelist). An attacker can construct a crafted Iced model that uses Java gadgets and leads to arbitrary code execution when imported to the H2O platform.

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость классов Iced платформы машинного обучения H2O, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 47%
0.00241
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-502