CVE-2023-6016: H2O Remote Code Execution via POJO Model Import
Published Nov 16, 2023
·Updated
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
Affected Software
1 affected component
h2o h2o
Event History
Nov 16, 2023
CVE Published
04:06 PM
Data Sourced
04:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-6016?
CVE-2023-6016 is a vulnerability that allows an attacker to gain remote code execution on a server hosting the H2O dashboard through its POJO model import feature.
2
How severe is CVE-2023-6016?
CVE-2023-6016 is classified as a critical vulnerability with a severity rating of 10 out of 10.
3
What software is affected by CVE-2023-6016?
The H2O software is affected by CVE-2023-6016.
4
How can an attacker exploit CVE-2023-6016?
An attacker can exploit CVE-2023-6016 by using the POJO model import feature of the H2O dashboard to gain remote code execution on the server.
5
Is there a fix for CVE-2023-6016?
It is recommended to update the H2O software to the latest version to fix CVE-2023-6016.