Vulnerability Description
An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthorized takeover.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| H2O | H2O | 3.45.0.6386 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/7c1b7f27-52f3-4b4b-9d81-e277f5e0ab6bExploitIssue TrackingThird Party Advisory
- https://huntr.com/bounties/7c1b7f27-52f3-4b4b-9d81-e277f5e0ab6bExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2024-1456?
CVE-2024-1456 is a vulnerability with a CVSS score of 7.1 (HIGH). An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthori...
How severe is CVE-2024-1456?
CVE-2024-1456 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-1456?
Check the references section above for vendor advisories and patch information. Affected products include: H2O H2O.