CVE-2024-8616

CVSS 3.0 Score 8.2 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 73

Summary

CVE-2024-8616 is a file overwrite vulnerability affecting h2oai's h2o-3 version 3.46.0. The issue lies within the `/99/Models/{name}/json` endpoint, where the `mexport.dir` user-controllable parameter in the `exportModelDetails` function of `ModelsHandler.java` is used to determine the file path for writing model details. Maliciously crafted requests can exploit this vulnerability to overwrite files at arbitrary locations on the target server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share