An attacker is able to read any file on the server hosting the H2O dashboard without any authentication.
References
| Link | Resource |
|---|---|
| https://huntr.com/bounties/380fce33-fec5-49d9-a101-12c972125d8c | Exploit |
Configurations
Information
Published : 2023-11-16 17:15
Updated : 2023-11-24 23:06
NVD link : CVE-2023-6038
Mitre link : CVE-2023-6038
JSON object : View
Products Affected
h2o
- h2o
CWE
CWE-862
Missing Authorization
