External Control of File Name or Path in h2oai/h2o-3
CVE-2023-6569

9.3CRITICAL

Key Information:

Vendor

H2oai

Vendor
CVE Published:
14 December 2023

What is CVE-2023-6569?

The vulnerability in H2O-3 allows an attacker to manipulate file names or paths externally, leading to potential unauthorized file access and manipulation. This flaw could compromise the integrity of data and applications that rely on safe file handling practices, posing significant risks to systems utilizing H2O.ai solutions.

Affected Version(s)

h2oai/h2o-3 <= unspecified

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

CVSS V3.0

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-6569 : External Control of File Name or Path in h2oai/h2o-3