Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS01OG0zLXJjdnAtZjl3d84AA9ZT
h2o vulnerable to unexpected POST request shutting down server
In h2oai/h2o-3 version 3.46.0, the run_tool
command in the rapids
component allows the main
function of any class under the water.tools
namespace to be called. One such class, MojoConvertTool
, crashes the server when invoked with an invalid argument, causing a denial of service.
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01OG0zLXJjdnAtZjl3d84AA9ZT
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 5 months ago
Updated: 5 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Identifiers: GHSA-58m3-rcvp-f9ww, CVE-2024-5979
References:
- https://nvd.nist.gov/vuln/detail/CVE-2024-5979
- https://huntr.com/bounties/d80a2139-fc03-44b7-b739-de41e323b458
- https://github.com/advisories/GHSA-58m3-rcvp-f9ww
Affected Packages
pypi:h2o
Dependent packages: 14Dependent repositories: 393
Downloads: 250,506 last month
Affected Version Ranges: <= 3.46.0
No known fixed version
All affected versions: