First published: Thu Nov 16 2023(Updated: )
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
H2o H2o |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6016 is a vulnerability that allows an attacker to gain remote code execution on a server hosting the H2O dashboard through its POJO model import feature.
CVE-2023-6016 is classified as a critical vulnerability with a severity rating of 10 out of 10.
The H2O software is affected by CVE-2023-6016.
An attacker can exploit CVE-2023-6016 by using the POJO model import feature of the H2O dashboard to gain remote code execution on the server.
It is recommended to update the H2O software to the latest version to fix CVE-2023-6016.