H2O是一个用于分布式、可扩展机器学习的内存平台。 H2O存在安全漏洞,该漏洞源于存在存储型跨站脚本(XSS)漏洞。攻击者可利用该漏洞造成本地文件包含。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| h2oai | h2oai/h2o-3 | unspecified ~ latest | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-6016 | H2O Remote Code Execution via POJO Model Import | |
| CVE-2023-6017 | H2O S3 Bucket Takeover | |
| CVE-2023-6038 | Local File Inclusion in h2oai/h2o-3 |
No comments yet