Denial of Service via Invalid Argument in h2oai/h2o-3
Vulnerability Description
In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with an invalid argument, causing a denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5979
Credits & Attribution
No credits recorded in the NVD database.
References
More from h2oai
View All →Affected Vendor
h2oai
View all reports →