CVE-2024-10572
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 400
Summary
CVE-2024-10572 is a vulnerability affecting version 3.46.0.1 of the h2oai/h2o-3 package, specifically the `run_tool` command. The issue arises from the exposure of classes in the `water.tools` package through the `ast` parser. Among these classes is the `XGBoostLibExtractTool`, which can be exploited by attackers to shut down the server and write large files to arbitrary directories, resulting in a denial of service.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.