GHSA-47f6-5p7h-5f3h

Suggest an improvement
Source
https://github.com/advisories/GHSA-47f6-5p7h-5f3h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-47f6-5p7h-5f3h
Aliases
  • CVE-2024-6854
Published
2025-03-20T12:32:45Z
Modified
2025-03-20T20:18:45.438920Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
H2O Vulnerable to Arbitrary File Overwrite via File Export
Details

In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to overwrite any file on the target server with a trained model file, although the content of the overwrite is not controllable by the attacker.

Database specific
{
    "nvd_published_at": "2025-03-20T10:15:34Z",
    "cwe_ids": [
        "CWE-36"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-20T19:53:19Z"
}
References

Affected packages

PyPI / h2o

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.32.1.1
Last affected
3.46.0

Affected versions

3.*

3.32.1.1
3.32.1.2
3.32.1.3
3.32.1.4
3.32.1.5
3.32.1.6
3.32.1.7
3.34.0.3
3.34.0.7
3.34.0.8
3.36.0.2
3.36.0.3
3.36.0.4
3.36.1.1
3.36.1.2
3.36.1.3
3.36.1.4
3.36.1.5
3.38.0.1
3.38.0.2
3.38.0.3
3.38.0.4
3.40.0.1
3.40.0.2
3.40.0.3
3.40.0.4
3.42.0.1
3.42.0.2
3.42.0.3
3.42.0.4
3.44.0.1
3.44.0.2
3.44.0.3

Maven / ai.h2o:h2o-core

Package

Name
ai.h2o:h2o-core
View open source insights on deps.dev
Purl
pkg:maven/ai.h2o/h2o-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.32.1.1
Last affected
3.46.0

Affected versions

3.*

3.32.1.1
3.32.1.2
3.32.1.3
3.32.1.4
3.32.1.5
3.32.1.6
3.32.1.7
3.34.0.1
3.34.0.3
3.34.0.4
3.34.0.5
3.34.0.6
3.34.0.7
3.34.0.8
3.35.0.2
3.36.0.1
3.36.0.2
3.36.0.3
3.36.0.4
3.36.1.1
3.36.1.2
3.36.1.3
3.36.1.4
3.36.1.5
3.38.0.1
3.38.0.2
3.38.0.3
3.38.0.4
3.40.0.1
3.40.0.2
3.40.0.3
3.40.0.4
3.42.0.1
3.42.0.2
3.42.0.3
3.42.0.4
3.44.0.1
3.44.0.2
3.44.0.3