Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-gqrq-j6pm-98c2: External Control of File Name or Path in h2oai/h2o-3

Remote unauthenticated attackers can overwrite arbitrary server files with attacker-controllable data. The data that the attacker can control is not entirely arbitrary. h2o writes a CSV/XLS/etc file to disk, so the attacker data is wrapped in quotations and starts with "C1", if they’re exporting as CSV.

ghsa
#git#auth

External Control of File Name or Path in h2oai/h2o-3

Critical severity GitHub Reviewed Published Dec 14, 2023 to the GitHub Advisory Database • Updated Dec 15, 2023

Related news

CVE-2023-6569

External Control of File Name or Path in h2oai/h2o-3