Логотип exploitDog
bind:CVE-2024-6854
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-6854

Количество 2

Количество 2

nvd логотип

CVE-2024-6854

11 месяцев назад

In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to overwrite any file on the target server with a trained model file, although the content of the overwrite is not controllable by the attacker.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-47f6-5p7h-5f3h

11 месяцев назад

H2O Vulnerable to Arbitrary File Overwrite via File Export

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-6854

In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to overwrite any file on the target server with a trained model file, although the content of the overwrite is not controllable by the attacker.

CVSS3: 7.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-47f6-5p7h-5f3h

H2O Vulnerable to Arbitrary File Overwrite via File Export

CVSS3: 7.1
0%
Низкий
11 месяцев назад

Уязвимостей на страницу