Vulnerabilities (CVE)

Filtered by vendor H2o Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6569 1 H2o 1 H2o 2023-12-18 N/A 8.2 HIGH
External Control of File Name or Path in h2oai/h2o-3
CVE-2023-6016 1 H2o 1 H2o 2023-11-28 N/A 9.8 CRITICAL
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
CVE-2023-6013 1 H2o 1 H2o 2023-11-28 N/A 5.4 MEDIUM
H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.
CVE-2023-6017 1 H2o 1 H2o 2023-11-28 N/A 7.1 HIGH
H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.
CVE-2023-6038 1 H2o 1 H2o 2023-11-24 N/A 7.5 HIGH
An attacker is able to read any file on the server hosting the H2O dashboard without any authentication.