H2O S3 Bucket Takeover
CVE-2023-6017
7.1HIGH
What is CVE-2023-6017?
H2O contains a vulnerability where it improperly manages a reference to an S3 bucket that has been deleted. This mismanagement can enable attackers to assume control over the S3 bucket URL, potentially leading to unauthorized access to sensitive data or resources linked to that bucket. It is essential for users of H2O to review their configurations and ensure that all cloud resource references are valid and secure.
Affected Version(s)
h2oai/h2o-3 <= unspecified
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
