In h2oai/h2o-3 version 3.46.0, the run_tool
command in the rapids
component allows the main
function of any class under the water.tools
namespace to be called. One such class, MojoConvertTool
, crashes the server when invoked with an invalid argument, causing a denial of service.
{ "nvd_published_at": "2024-06-27T19:15:18Z", "cwe_ids": [ "CWE-400" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-06-28T21:09:00Z" }