CVE-2024-6863
- EPSS 0.33%
- Veröffentlicht 20.03.2025 10:10:30
- Zuletzt bearbeitet 15.07.2025 15:52:34
In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of their choosing. The chosen key can also be overwritten, resulting in ransomware-like behavior. This...
CVE-2024-8616
- EPSS 0.51%
- Veröffentlicht 20.03.2025 10:10:20
- Zuletzt bearbeitet 15.07.2025 15:49:27
In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the `exportModelDetails` function in `ModelsHandler.java`, where the user-controllable `mexpo...
CVE-2024-10550
- EPSS 0.59%
- Veröffentlicht 20.03.2025 10:10:11
- Zuletzt bearbeitet 14.07.2025 13:49:13
A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker ...
CVE-2024-6854
- EPSS 0.69%
- Veröffentlicht 20.03.2025 10:09:57
- Zuletzt bearbeitet 15.07.2025 15:55:02
In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to ...
CVE-2024-10572
- EPSS 0.64%
- Veröffentlicht 20.03.2025 10:09:28
- Zuletzt bearbeitet 15.10.2025 13:15:36
In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGBoostLibExtractTool` class, which can be exploited to shut down the server and write large files to ar...
CVE-2024-10553
- EPSS 1.44%
- Veröffentlicht 20.03.2025 10:09:04
- Zuletzt bearbeitet 14.07.2025 13:43:55
A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization of untrusted data. The vulnerability exists in the endpoints POST /99/ImportSQLTable and POST /3/SaveT...
CVE-2024-7765
- EPSS 0.72%
- Veröffentlicht 20.03.2025 10:08:46
- Zuletzt bearbeitet 01.04.2025 20:33:36
In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes unresponsive due to memory exhaustion and a large number of concurrent slow-running job...
CVE-2024-8862
- EPSS 1.33%
- Veröffentlicht 14.09.2024 20:15:11
- Zuletzt bearbeitet 20.09.2024 15:47:10
A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the component JDBC Connection Handler. The manipulation of the argument qu...
CVE-2024-45758
- EPSS 0.9%
- Veröffentlicht 06.09.2024 16:15:03
- Zuletzt bearbeitet 29.09.2025 13:56:10
H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the ImportSQLTable URI with a JSON docu...
CVE-2024-5979
- EPSS 0.79%
- Veröffentlicht 27.06.2024 19:15:18
- Zuletzt bearbeitet 15.10.2025 13:15:48
In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid...