CVE-2023-6017

EUVD-2023-58282
H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
@huntr_aiCNA
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
Affected Products (NVD)
VendorProductVersion
h2oh2o
-
𝑥
= Vulnerable software versions
Common Weakness Enumeration