GHSA-hrmc-jmp7-mpm2 · Severity: critical · Ecosystem: maven — H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL
H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when an attacker has access to post to the ImportSQLTable URI with a JSON document containing a connection_url property with any typical JDBC Connection URL attack payload such as one that uses queryInterceptors.
Conclusion & alert: CVE-2024-45758 is rated Exploit Available (59.5/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.08%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.21% | 0.08% | -0.13% |
| 2 | 2025-11-18 | 0.07% | 0.21% | +0.14% |
| 3 | 2025-03-17 | — | 0.07% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-hrmc-jmp7-mpm2 · Severity: critical · Ecosystem: maven — H2O.ai H2O vulnerable to deserialization attacks via a JDBC Connection URL
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-45758: 1 source package rows (h2o); 2 state rows across 1 repos (edge-community); fixed 0, open 2. | https://security.alpinelinux.org/vuln/CVE-2024-45758 |
| URL | Tags |
|---|---|
| https://gist.github.com/AfterSnows/c24ca3c26dc89ab797e610e92a6a9acb | Third Party Advisory |
| https://spear-shield.notion.site/Unauthenticated-Remote-Code-Execution-via-Unrestricted-JDBC-Connection-87a958a4874044199cbb86422d1f6068 | Exploit Third Party Advisory |