CVE-2024-8616: H2O Vulnerable to Arbitrary File Overwrite
In h2oai/h2o-3 version 3.46.0, the /99/Models/{name}/json
endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the exportModelDetails
function in ModelsHandler.java
, where the user-controllable mexport.dir
parameter is used to specify the file path for writing model details. This can lead to overwriting files at arbitrary locations on the host system.
References
Code Behaviors & Features
Detect and mitigate CVE-2024-8616 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →