In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial of service.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1927 In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial of service.
Github GHSA Github GHSA GHSA-58m3-rcvp-f9ww h2o vulnerable to unexpected POST request shutting down server
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 15 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
References

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00157}

epss

{'score': 0.0017}


Tue, 15 Jul 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared H2o
H2o h2o
CPEs cpe:2.3:a:h2o:h2o:3.46.0:*:*:*:*:*:*:*
Vendors & Products H2o
H2o h2o

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-10-15T12:49:44.742Z

Reserved: 2024-06-13T17:38:41.146Z

Link: CVE-2024-5979

cve-icon Vulnrichment

Updated: 2024-08-01T21:25:03.168Z

cve-icon NVD

Status : Modified

Published: 2024-06-27T19:15:18.560

Modified: 2025-10-15T13:15:48.333

Link: CVE-2024-5979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T16:01:15Z