漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Remote Arbitrary File Write with Arbitrary Data in h2oai/h2o-3
Vulnerability Description
A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the server. This is achieved by exploiting the `/3/Parse` endpoint to inject attacker-controlled data as the header of an empty file, which is then exported using the `/3/Frames/framename/export` endpoint. The impact of this vulnerability includes the potential for remote code execution and complete access to the system running h2o-3, as attackers can overwrite critical files such as private SSH keys or script files.
CVSS Information
N/A
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
H2O 安全漏洞
Vulnerability Description
H2O是H2O.ai开源的一个用于分布式、可扩展机器学习的内存平台。 H2O 3.46.0.1版本存在安全漏洞,该漏洞源于攻击者可利用/3/Parse和/3/Frames/framename/export端点向服务器任意文件写入数据,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A