Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6902 | In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the `exportModelDetails` function in `ModelsHandler.java`, where the user-controllable `mexport.dir` parameter is used to specify the file path for writing model details. This can lead to overwriting files at arbitrary locations on the host system. |
Github GHSA |
GHSA-g48v-3p35-88jr | H2O Vulnerable to Arbitrary File Overwrite |
Tue, 15 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
H2o
H2o h2o |
|
| CPEs | cpe:2.3:a:h2o:h2o:3.46.0:*:*:*:*:*:*:* | |
| Vendors & Products |
H2o
H2o h2o |
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the `exportModelDetails` function in `ModelsHandler.java`, where the user-controllable `mexport.dir` parameter is used to specify the file path for writing model details. This can lead to overwriting files at arbitrary locations on the host system. | |
| Title | Arbitrary File Overwrite in h2oai/h2o-3 | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:23:06.601Z
Reserved: 2024-09-09T18:32:04.567Z
Link: CVE-2024-8616
Updated: 2025-03-20T17:51:49.690Z
Status : Analyzed
Published: 2025-03-20T10:15:43.590
Modified: 2025-07-15T15:49:27.497
Link: CVE-2024-8616
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA