External Control of File Name or Path in h2oai/h2o-3
CVE-2023-6569
9.3CRITICAL
What is CVE-2023-6569?
The vulnerability in H2O-3 allows an attacker to manipulate file names or paths externally, leading to potential unauthorized file access and manipulation. This flaw could compromise the integrity of data and applications that rely on safe file handling practices, posing significant risks to systems utilizing H2O.ai solutions.
Affected Version(s)
h2oai/h2o-3 <= unspecified
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
CVSS V3.0
Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
