H2o

H2o

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Veröffentlicht 21.09.2025 09:33:19
  • Zuletzt bearbeitet 08.10.2025 19:58:40

A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of the argument connection_url leads to deserialization. The attack may be...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 21.09.2025 09:33:16
  • Zuletzt bearbeitet 08.10.2025 20:04:01

A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack ma...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 21.09.2025 09:00:09
  • Zuletzt bearbeitet 08.10.2025 20:05:02

A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises from improper handling of JDBC connection parameters, which can be expl...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 20.03.2025 10:11:32
  • Zuletzt bearbeitet 15.10.2025 13:15:35

A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint uses a user-specified string to construct a regular expression, which is then applied to another user-specified strin...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 20.03.2025 10:11:04
  • Zuletzt bearbeitet 26.03.2025 16:10:51

A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by ...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 20.03.2025 10:10:48
  • Zuletzt bearbeitet 15.10.2025 13:15:52

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 20.03.2025 10:10:30
  • Zuletzt bearbeitet 15.07.2025 15:52:34

In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of their choosing. The chosen key can also be overwritten, resulting in ransomware-like behavior. This...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 20.03.2025 10:10:20
  • Zuletzt bearbeitet 15.07.2025 15:49:27

In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the `exportModelDetails` function in `ModelsHandler.java`, where the user-controllable `mexpo...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 20.03.2025 10:10:11
  • Zuletzt bearbeitet 14.07.2025 13:49:13

A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker ...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 20.03.2025 10:09:57
  • Zuletzt bearbeitet 15.07.2025 15:55:02

In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to ...