PT-2024-31754 · H2O.Ai · H2O
Aftersnows
+2
·
Published
2024-09-06
·
Updated
2025-09-29
·
CVE-2024-45758
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
H2O.ai H2O versions 3.46.0.4 and earlier
Description:
The issue allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the "ImportSQLTable" URI with a JSON document containing a
connection url property with any typical JDBC Connection URL attack payload.Recommendations:
For versions 3.46.0.4 and earlier, update to a patched version to resolve the issue. As a temporary workaround, consider restricting access to the ImportSQLTable URI to minimize the risk of exploitation. Avoid using the
connection url property in the affected JSON documents until the issue is resolved.Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
H2O