CVE-2024-8616: H2O Vulnerable to Arbitrary File Overwrite
In h2oai/h2o-3 version 3.46.0, the /99/Models/{name}/json
endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the exportModelDetails
function in ModelsHandler.java
, where the user-controllable mexport.dir
parameter is used to specify the file path for writing model details. This can lead to overwriting files at arbitrary locations on the host system.
References
Detect and mitigate CVE-2024-8616 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →