← volver
CVE-2023-6038criticalexplotación observadaCWE-862

Local File Inclusion in h2oai/h2o-3

65Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 9.3epss 4.3%
de la publicación al arma
Publicada en NVD16 nov
VulnCheck+67d
probabilidad de explotación
4.3%top 10% de las CVE
explotación observada
VulnCheck
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Productos afectados
h2oai · h2oai/h2o-3