Remote Code Execution Vulnerability in H2O-3 REST API by H2O.ai
CVE-2025-5662
9.8CRITICAL
What is CVE-2025-5662?
A deserialization vulnerability found in the H2O-3 REST API allows attackers to exploit improper validation of JDBC connection parameters, leading to remote code execution. This issue affects all versions of H2O-3 prior to 3.46.0.8 and is associated with the MySQL JDBC Driver version 8.0.19 and JDK version 8u112. The vulnerability presents significant risks by enabling unauthorized commands to be executed in the application context, highlighting the importance of updating to the patched version 3.46.0.8 to mitigate potential threats.
Affected Version(s)
h2oai/h2o-3 < 3.46.0.8
