7.1

CVE-2024-1456

Exploit

S3 Bucket Takeover in h2oai/h2o-3

An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthorized takeover.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
H2o ≫ H2o Version 3.45.0.6386
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.152
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@huntr.dev 7.1 1.8 5.2
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://huntr.com/bounties/7c1b7f27-52f3-4b4b-9d81-e277f5e0ab6b
Third Party Advisory
Exploit
Issue Tracking