Skip to main content

CVE-2023-6038

7.5
HIGHCVSS v3.1 Base Score
63.28%
MEDIUM RiskEPSS (98th percentile)

A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.

Published: 11/16/2023
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Score (Exploitation Probability)

63.28%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 63.28% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

Related Vulnerabilities