CVE-2024-7768
CVSS 3.0 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 400
Summary
CVE-2024-7768 is a denial-of-service vulnerability affecting the `/3/ImportFiles` endpoint in h2oai/h2o-3 version 3.46.1. An attacker can exploit this issue by setting the endpoint's `path` parameter to recursively reference itself. The server, in response, will repeatedly call its own endpoint, leading to an excessive buildup in the request queue and rendering the server unable to process further requests.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.