Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13305 | A vulnerability in the S3 bucket configuration for h2oai/h2o-3 allows public write access to the 'h2o-release' bucket. This issue affects all versions and could enable an attacker to overwrite any file in the bucket. As users download binary files such as JARs from this bucket, this vulnerability could lead to remote code execution (RCE) on any user who uses the application. Additionally, an attacker could modify the documentation to include malicious download links. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No reference.
Tue, 20 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Authorization in h2oai/h2o-3 | |
| References |
|
|
| Metrics |
ssvc
|
Tue, 20 May 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_0
|
Tue, 20 May 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the S3 bucket configuration for h2oai/h2o-3 allows public write access to the 'h2o-release' bucket. This issue affects all versions and could enable an attacker to overwrite any file in the bucket. As users download binary files such as JARs from this bucket, this vulnerability could lead to remote code execution (RCE) on any user who uses the application. Additionally, an attacker could modify the documentation to include malicious download links. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Tue, 06 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the S3 bucket configuration for h2oai/h2o-3 allows public write access to the 'h2o-release' bucket. This issue affects all versions and could enable an attacker to overwrite any file in the bucket. As users download binary files such as JARs from this bucket, this vulnerability could lead to remote code execution (RCE) on any user who uses the application. Additionally, an attacker could modify the documentation to include malicious download links. | |
| Title | Missing Authorization in h2oai/h2o-3 | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: @huntr_ai
Published:
Updated: 2025-05-20T10:17:12.083Z
Reserved: 2025-01-28T13:18:01.044Z
Link: CVE-2025-0782
Updated:
Status : Rejected
Published: 2025-05-02T21:15:23.550
Modified: 2025-05-20T11:15:47.677
Link: CVE-2025-0782
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD