CVE-2025-0782: Missing Authorization in h2oai/h2o-3
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0782?
CVE-2025-0782 has been classified as a high severity vulnerability due to its potential to allow unauthorized public write access to sensitive files in the S3 bucket.
How do I fix CVE-2025-0782?
To fix CVE-2025-0782, reconfigure the S3 bucket permissions to ensure that public write access is disabled.
What impact does CVE-2025-0782 have on my files?
CVE-2025-0782 allows an attacker to overwrite any file in the affected 'h2o-release' S3 bucket, potentially compromising your application's integrity.
Which versions are affected by CVE-2025-0782?
CVE-2025-0782 affects all versions of h2oai/h2o-3, allowing for public write access regardless of the version.
Is CVE-2025-0782 exploitable remotely?
Yes, CVE-2025-0782 is exploitable remotely, allowing attackers to manipulate files in the S3 bucket without needing direct access to the system.