Home » Database

AVID-2026-R1328

Description

External Control of File Name or Path in h2oai/h2o-3 (CVE-2023-6569)

Details

External Control of File Name or Path in h2oai/h2o-3

Reason for inclusion in AVID: CVE-2023-6569 describes external control of a file name or path in h2oai/h2o-3, a machine learning framework. This is a software vulnerability within a component used to build/train/deploy AI systems, with remote exploitation potential (network-based) and impact on availability and integrity. It directly concerns AI software stacks and their pipelines, not hardware/firmware. The AVID candidate includes official CVE context and references, providing sufficient evidence for inclusion.

References

Affected or Relevant Artifacts

  • Developer: h2oai
  • Deployer: h2oai
  • Artifact Details:
TypeName
Systemh2oai/h2o-3

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
Base Score9.3
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeCHANGED
Confidentiality ImpactNONE
Integrity Impact🟢 Low
Availability Impact🔴 High

CWE

IDDescription
CWE-73CWE-73 External Control of File Name or Path

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2023-12-14
  • Version: 0.3.3
  • AVID Entry