CVE-2024-10572

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-10572 is a vulnerability affecting version 3.46.0.1 of the h2oai/h2o-3 package, specifically the `run_tool` command. The issue arises from the exposure of classes in the `water.tools` package through the `ast` parser. Among these classes is the `XGBoostLibExtractTool`, which can be exploited by attackers to shut down the server and write large files to arbitrary directories, resulting in a denial of service.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share