H2O-3GHSA-gqrq-j6pm-98c2
External Control of File Name or Path in h2oai/h2o-3
Critical9.3CVE-2023-6569 · Published Dec 14, 2023 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| h2o PyPI | < 3.46.0.1 | 3.46.0.1 |
Details and references
Remote unauthenticated attackers can overwrite arbitrary server files with attacker-controllable data. The data that the attacker can control is not entirely arbitrary. h2o writes a CSV/XLS/etc file to disk, so the attacker data is wrapped in quotations and starts with "C1", if they're exporting as CSV.
More H2O-3 advisories
All H2O-3| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 62024 | Arbitrary system path lookup in h20 CVE-2024-5550Medium5.3no fix yet | Medium5.3 | No fix yet |
| Jun 272024 | h2o vulnerable to unexpected POST request shutting down server CVE-2024-5979High7.5no fix yet | High7.5 | No fix yet |
| Sep 62024 | H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL CVE-2024-45758Critical9.1no fix yet | Critical9.1 | No fix yet |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint CVE-2024-10550High7.5no fix yet | High7.5 | No fix yet |
| Mar 202025 | H2O Deserialization of Untrusted Data Vulnerability CVE-2024-10553Critical9.8fixed in 3.46.0.6 | Critical9.8 | 3.46.0.6 |
| Mar 202025 | H2O Vulnerable to Denial of Service (DoS) and File Write CVE-2024-10572High7.5no fix yet | High7.5 | No fix yet |