H2O是H2O.ai开源的一个用于分布式、可扩展机器学习的内存平台。 H2O存在访问控制错误漏洞,该漏洞源于访问控制不会检测和禁止由具有欺骗源地址的数据包传达的HTTP请求,允许攻击者从地址访问控制拒绝的地址执行HTTP请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-45402 | 8.6 HIGH | Picotls double free |
| CVE-2024-45396 | 7.5 HIGH | Quicly assertion failures |
| CVE-2024-45403 | 3.7 LOW | H2O assertion failure when HTTP/3 requests are cancelled |
| CVE-2024-25622 | 3.1 LOW | H2O ignores headers configuration directives |
No comments yet