H2O Vulnerable to Denial of Service (DoS) and File Write
High severity
GitHub Reviewed
Published
Mar 20, 2025
to the GitHub Advisory Database
•
Updated Mar 20, 2025
Description
Published by the National Vulnerability Database
Mar 20, 2025
Published to the GitHub Advisory Database
Mar 20, 2025
Reviewed
Mar 20, 2025
Last updated
Mar 20, 2025
In h2oai/h2o-3 version 3.46.0.1, the
run_tool
command exposes classes in thewater.tools
package through theast
parser. This includes theXGBoostLibExtractTool
class, which can be exploited to shut down the server and write large files to arbitrary directories, leading to a denial of service.References