Remote Code Execution Risk in H2O.ai H2O-3 Product
CVE-2024-5986
9.1CRITICAL
What is CVE-2024-5986?
A vulnerability in H2O.ai's H2O-3 version 3.46.0.1 allows remote attackers to exploit the '/3/Parse' endpoint and inject malicious data into file headers. This allows attackers to overwrite any file on the server, potentially leading to remote code execution and unauthorized access to critical system files, such as SSH keys and scripts, severely compromising system integrity.
Affected Version(s)
h2oai/h2o-3 <= unspecified
