H2o 3
by H2oai
Source repositories
CVEs (30)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-10572 | 0.00 | — | 0.01 | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGBoostLibExtractTool` class, which can be exploited to shut down the server and write large files to arbitrary directories, leading… | |||
| CVE-2024-10553 | 0.00 | — | 0.01 | Mar 20, 2025 | A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization of untrusted data. The vulnerability exists in the endpoints POST /99/ImportSQLTable and POST /3/SaveToHiveTable, where… | |||
| CVE-2024-7765 | 0.00 | — | 0.01 | Mar 20, 2025 | In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes unresponsive due to memory exhaustion and a large number of concurrent slow-running jobs. This issue arises from the… | |||
| CVE-2024-8862 | 0.00 | — | 0.01 | Sep 14, 2024 | A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the component JDBC Connection Handler. The manipulation of the argument query leads to deserialization.… | |||
| CVE-2024-5979 | 0.00 | — | 0.01 | Jun 27, 2024 | In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial… | |||
| CVE-2024-5550 | 0.00 | — | 0.01 | Jun 6, 2024 | In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulnerability allows any remote user to view full paths in the entire file system where h2o-3 is hosted. Specifically, the issue… | |||
| CVE-2024-1456 | 0.00 | — | 0.00 | Apr 16, 2024 | An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthorized takeover. | |||
| CVE-2023-6569 | 0.00 | — | 0.01 | Dec 14, 2023 | External Control of File Name or Path in h2oai/h2o-3 | |||
| CVE-2023-6013 | 0.00 | — | 0.01 | Nov 16, 2023 | H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack. | |||
| CVE-2023-6017 | 0.00 | — | 0.01 | Nov 16, 2023 | H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL. |
- CVE-2024-10572Mar 20, 2025risk 0.00cvss —epss 0.01
In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGBoostLibExtractTool` class, which can be exploited to shut down the server and write large files to arbitrary directories, leading…
- CVE-2024-10553Mar 20, 2025risk 0.00cvss —epss 0.01
A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization of untrusted data. The vulnerability exists in the endpoints POST /99/ImportSQLTable and POST /3/SaveToHiveTable, where…
- CVE-2024-7765Mar 20, 2025risk 0.00cvss —epss 0.01
In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes unresponsive due to memory exhaustion and a large number of concurrent slow-running jobs. This issue arises from the…
- CVE-2024-8862Sep 14, 2024risk 0.00cvss —epss 0.01
A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of the component JDBC Connection Handler. The manipulation of the argument query leads to deserialization.…
- CVE-2024-5979Jun 27, 2024risk 0.00cvss —epss 0.01
In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial…
- CVE-2024-5550Jun 6, 2024risk 0.00cvss —epss 0.01
In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulnerability allows any remote user to view full paths in the entire file system where h2o-3 is hosted. Specifically, the issue…
- CVE-2024-1456Apr 16, 2024risk 0.00cvss —epss 0.00
An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthorized takeover.
- CVE-2023-6569Dec 14, 2023risk 0.00cvss —epss 0.01
External Control of File Name or Path in h2oai/h2o-3
- CVE-2023-6013Nov 16, 2023risk 0.00cvss —epss 0.01
H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.
- CVE-2023-6017Nov 16, 2023risk 0.00cvss —epss 0.01
H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.
Page 2 of 2