漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Deserialization of Untrusted Data in h2oai/h2o-3
Vulnerability Description
A vulnerability in the h2oai/h2o-3 repository allows attackers to exploit deserialization of untrusted data, potentially leading to arbitrary code execution and reading of system files. This issue affects the latest master branch version 3.47.0.99999. The vulnerability arises from the ability to bypass regular expression filters intended to prevent malicious parameter injection in JDBC connections. Attackers can manipulate spaces between parameters to evade detection, allowing for unauthorized file access and code execution. The vulnerability is addressed in version 3.46.0.8.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
H2O 代码问题漏洞
Vulnerability Description
H2O是H2O.ai开源的一个用于分布式、可扩展机器学习的内存平台。 H2O 3.47.0.99999版本存在代码问题漏洞,该漏洞源于反序列化问题,可能导致任意代码执行和系统文件读取。
CVSS Information
N/A
Vulnerability Type
N/A