漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Denial of Service in h2oai/h2o-3
Vulnerability Description
A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests.
CVSS Information
N/A
Vulnerability Type
远程资源无超时同步访问
Vulnerability Title
H2O 安全漏洞
Vulnerability Description
H2O是H2O.ai开源的一个用于分布式、可扩展机器学习的内存平台。 H2O 3.46.0版本存在安全漏洞,该漏洞源于typeahead端点在验证指定资源存在时未设置超时,攻击者可以通过发送多个请求使应用程序阻塞并无法响应其他请求。
CVSS Information
N/A
Vulnerability Type
N/A