PyPi: H2o

CVE-2024-5979

Safety vulnerability ID: 72091

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jun 27, 2024 Updated at Nov 02, 2024
Scan your Python projects for vulnerabilities →

Advisory

Affected versions of H2o are vulnerable to CVE-2024-5979: The 'run_tool' command in the 'rapids' component allows the 'main' function of any class under the 'water.tools' namespace to be called. One such class, 'MojoConvertTool', crashes the server when invoked with an invalid argument, causing a denial of service.
The vulnerable code is found in /h2o/backend/bin/h2o.jar

Affected package

h2o

Latest version: 3.46.0.6

H2O, Fast Scalable Machine Learning, for python

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application