Remote Code Execution Risk in H2O.ai H2O-3 Product
CVE-2024-5986
9.1CRITICAL
What is CVE-2024-5986?
A vulnerability in H2O.ai's H2O-3 version 3.46.0.1 allows remote attackers to exploit the '/3/Parse' endpoint and inject malicious data into file headers. This allows attackers to overwrite any file on the server, potentially leading to remote code execution and unauthorized access to critical system files, such as SSH keys and scripts, severely compromising system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
h2oai/h2o-3 <= unspecified
References
CVSS V3.0
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
