H2O S3 Bucket Takeover
CVE-2023-6017
7.1HIGH
What is CVE-2023-6017?
H2O contains a vulnerability where it improperly manages a reference to an S3 bucket that has been deleted. This mismanagement can enable attackers to assume control over the S3 bucket URL, potentially leading to unauthorized access to sensitive data or resources linked to that bucket. It is essential for users of H2O to review their configurations and ensure that all cloud resource references are valid and secure.
Affected Version(s)
h2oai/h2o-3 <= unspecified
