CVE-2023-6038
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/11/2023
Last modified:
16/04/2024
Description
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:h2o:h2o:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



