ai.h2o:h2o-core@3.46.0.5 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the ai.h2o:h2o-core package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Deserialization of Untrusted Data

Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to improper input validation. An attacker can construct a crafted Iced model that uses Java gadgets and leads to arbitrary code execution when imported to the H2O platform.

How to fix Deserialization of Untrusted Data?

There is no fixed version for ai.h2o:h2o-core.

[0,)
  • H
Denial Of Service

Affected versions of this package are vulnerable to Denial Of Service through the run_tool command in the rapids component, which allows the main function of any class under the water.tools namespace to be called. An attacker can crash the server by invoking the MojoConvertTool class with an invalid argument.

How to fix Denial Of Service?

There is no fixed version for ai.h2o:h2o-core.

[0,)