h2oai / h2o-3

H2O is an Open Source, Distributed, Fast & Scalable Machine Learning Platform: Deep Learning, Gradient Boosting (GBM) & XGBoost, Random Forest, Generalized Linear Modeling (GLM with Elastic Net), K-Means, PCA, Generalized Additive Models (GAM), RuleFit, Support Vector Machine (SVM), Stacked Ensembles, Automatic Machine Learning (AutoML), etc.
http://h2o.ai
Apache License 2.0
6.94k stars 2k forks source link

CVE-2024-8862 JDBC connector #16425

Closed arunaryasomayajula closed 1 month ago

arunaryasomayajula commented 1 month ago

H2O version, Operating System and Environment H2O3 version 3.46.0.1/4

https://support.h2o.ai/a/tickets/109536, https://nvd.nist.gov/vuln/detail/CVE-2024-8862

According to @krasinski , the link at the CVE report site is incorrect. He found the real fix here: https://spear-shield.notion.site/Unauthenticated-Remote-Code-Execution-via-Unrestricted-JDBC-Connection-87a958a4874044199cbb86422d1f6068

krasinski commented 1 month ago

CVE-2024-45758