Home » Database

AVID-2026-R1321

Description

H2O Local File Include (CVE-2023-6013)

Details

H2O is vulnerable to stored XSS vulnerability which can lead to a Local File Include attack.

Reason for inclusion in AVID: CVE-2023-6013 affects H2O-3, an AI platform component; the vuln is a network-accessible web vulnerability (XSS leading to Local File Include) that can impact AI software stacks used for model building/deployment. This is a security flaw in software components used in GP AI systems, with explicit CVE and CVSS signals.

References

Affected or Relevant Artifacts

  • Developer: h2oai
  • Deployer: h2oai
  • Artifact Details:
TypeName
Systemh2oai/h2o-3

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Base Score9.3
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
Confidentiality Impact🔴 High
Integrity Impact🟢 Low
Availability ImpactNONE

CWE

IDDescription
CWE-79CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2023-11-16
  • Version: 0.3.3
  • AVID Entry