CVE-2024-8616
CVSS 3.0 Score 8.2 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 73
Summary
CVE-2024-8616 is a file overwrite vulnerability affecting h2oai's h2o-3 version 3.46.0. The issue lies within the `/99/Models/{name}/json` endpoint, where the `mexport.dir` user-controllable parameter in the `exportModelDetails` function of `ModelsHandler.java` is used to determine the file path for writing model details. Maliciously crafted requests can exploit this vulnerability to overwrite files at arbitrary locations on the target server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.