HIGH 8.2 PyPI
H2O Vulnerable to Arbitrary File Overwrite
GHSA-g48v-3p35-88jr · CVE-2024-8616 · PYSEC-2026-1441
Published · Modified
Description
In h2oai/h2o-3 version 3.46.0, the /99/Models/{name}/json endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the exportModelDetails function in ModelsHandler.java, where the user-controllable mexport.dir parameter is used to specify the file path for writing model details. This can lead to overwriting files at arbitrary locations on the host system.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-8616
- PACKAGE https://github.com/h2oai/h2o-3
- WEB https://github.com/h2oai/h2o-3/blob/088190f9d0370a02a483fca68d8dc89c996b4f83/h2o-core/src/main/java/water/api/ModelsHandler.java#L310
- WEB https://huntr.com/bounties/aebf69a5-b9b1-4d2f-a8ff-902c11a8c97a
Ready to move
Start Securing
Free, no credit card | First findings in minutes