Lucene search

K
nvd[email protected]NVD:CVE-2024-1456
HistoryApr 16, 2024 - 12:15 a.m.

CVE-2024-1456

2024-04-1600:15:08
CWE-840
web.nvd.nist.gov
3
cve-2024-1456
s3 bucket
h2oai/h2o-3
unauthorized takeover

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

9.0%

An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket ‘http://s3.amazonaws.com/h2o-training’, which was found to be vulnerable to unauthorized takeover.

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

9.0%

Related for NVD:CVE-2024-1456