H2o 3
by H2oai
Source repositories
CVEs (30)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-6017 | Hig | 0.46 | 7.1 | 0.01 | Nov 16, 2023 | H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL. | ||
| CVE-2024-6863 | Med | 0.42 | 6.5 | 0.00 | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of their choosing. The chosen key can also be overwritten, resulting in ransomware-like behavior. This vulnerability makes it… | ||
| CVE-2024-5979 | Hig | 0.42 | 7.5 | 0.01 | Jun 27, 2024 | In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial… | ||
| CVE-2025-10769 | Med | 0.41 | 6.3 | 0.00 | Sep 21, 2025 | A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of the argument connection_url leads to deserialization. The attack may be launched remotely. The… | ||
| CVE-2025-10768 | Med | 0.41 | 6.3 | 0.00 | Sep 21, 2025 | A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack may be initiated remotely. The… | ||
| CVE-2024-8862 | Hig | 0.41 | 7.3 | 0.01 | Sep 14, 2024 | A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the component JDBC Connection Handler. The manipulation of the argument query leads to deserialization.… | ||
| CVE-2024-5550 | Med | 0.35 | 5.3 | 0.01 | Jun 6, 2024 | In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulnerability allows any remote user to view full paths in the entire file system where h2o-3 is hosted. Specifically, the issue… | ||
| CVE-2023-6013 | Med | 0.35 | 5.4 | 0.01 | Nov 16, 2023 | H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack. | ||
| CVE-2026-8752 | Med | 0.34 | 5.3 | 0.00 | May 17, 2026 | A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing a manipulation can lead to… | ||
| CVE-2026-8750 | Med | 0.34 | 5.3 | 0.01 | May 17, 2026 | A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disclosure. The attack can be… |
- risk 0.46cvss 7.1epss 0.01
H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.
- risk 0.42cvss 6.5epss 0.00
In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of their choosing. The chosen key can also be overwritten, resulting in ransomware-like behavior. This vulnerability makes it…
- risk 0.42cvss 7.5epss 0.01
In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLTable of the component H2 JDBC Driver. Such manipulation of the argument connection_url leads to deserialization. The attack may be launched remotely. The…
- risk 0.41cvss 6.3epss 0.00
A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack may be initiated remotely. The…
- risk 0.41cvss 7.3epss 0.01
A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the component JDBC Connection Handler. The manipulation of the argument query leads to deserialization.…
- risk 0.35cvss 5.3epss 0.01
In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulnerability allows any remote user to view full paths in the entire file system where h2o-3 is hosted. Specifically, the issue…
- risk 0.35cvss 5.4epss 0.01
H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.
- risk 0.34cvss 5.3epss 0.00
A weakness has been identified in h2oai h2o-3 up to 7402. This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.java of the component Rapids setproperty Primitive Handler. Executing a manipulation can lead to…
- risk 0.34cvss 5.3epss 0.01
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFile API. Such manipulation leads to information disclosure. The attack can be…
Page 2 of 2