← Back to browse · API

CVE-2023-6016

Severity
CRITICAL
CVSS
10.0
EPSS
0.30567
Risk score
50.7
CISA KEV
No
PoC
No
Published
2023-11-16
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2023-58281, GHSA-P3V8-5QC4-7P8R
Products
h2oai:h2oai/h2o-3 unspecified ≤latest
Sources
euvd EUVD-2023-58281

Description

An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.

References