High severity8.2NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-8616
CVE-2024-8616
Description
In h2oai/h2o-3 version 3.46.0, the /99/Models/{name}/json endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the exportModelDetails function in ModelsHandler.java, where the user-controllable mexport.dir parameter is used to specify the file path for writing model details. This can lead to overwriting files at arbitrary locations on the host system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
h2oPyPI | >= 3.10.4.1, <= 3.46.0 | — |
ai.h2o:h2o-coreMaven | >= 3.10.4.1, <= 3.46.0 | — |
Affected products
3- ghsa-coords2 versions
>= 3.10.4.1, <= 3.46.0+ 1 more
- (no CPE)range: >= 3.10.4.1, <= 3.46.0
- (no CPE)range: >= 3.10.4.1, <= 3.46.0
Patches
Vulnerability mechanics
References
4- huntr.com/bounties/aebf69a5-b9b1-4d2f-a8ff-902c11a8c97anvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-g48v-3p35-88jrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8616ghsaADVISORY
- github.com/h2oai/h2o-3/blob/088190f9d0370a02a483fca68d8dc89c996b4f83/h2o-core/src/main/java/water/api/ModelsHandler.javaghsaWEB
News mentions
0No linked articles in our index yet.