¡¾Îó²îͨ¸æ¡¿H2O-3 JDBC ²ÎÊýÈÆ¹ýÒý·¢·´ÐòÁл¯ RCE(CVE-2025-6544)
Ðû²¼Ê±¼ä 2025-09-23Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | H2O-3 JDBC ²ÎÊýÈÆ¹ýÒý·¢·´ÐòÁл¯ RCE | ||
CVE ID | CVE-2025-6544 | ||
Îó²îÀàÐÍ | ·´ÐòÁл¯ | ·¢Ã÷ʱ¼ä | 2025-09-23 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
H2O-3ÊÇÓÉH2O.ai¿ª·¢µÄ¿ªÔ´ÂþÑÜʽ»úеѧϰƽ̨£¬£¬£¬£¬Ö§³Ö´ó¹æÄ£Êý¾Ý´¦Öóͷ£Ó뽨ģ¡£¡£ËüÌṩÁËÆÕ±éµÄËã·¨£¬£¬£¬£¬°üÀ¨·ÖÀ࣬£¬£¬£¬»Ø¹é£¬£¬£¬£¬¾ÛÀ࣬£¬£¬£¬Òì³£¼ì²âºÍÉî¶Èѧϰ£¬£¬£¬£¬Äܹ»ÔÚ´óÊý¾ÝÇéÐÎϸßЧÔËÐС£¡£H2O-3Ö§³Ö¶àÖÖ±à³Ì½Ó¿Ú£¬£¬£¬£¬Èçpython£¬£¬£¬£¬R£¬£¬£¬£¬ScalaºÍJAVA£¬£¬£¬£¬Í¬Ê±ÓëSpark£¬£¬£¬£¬HadoopµÈÉú̬ϵͳ¼æÈÝ£¬£¬£¬£¬Àû±ã¼¯³Éµ½ÆóÒµµÄÊý¾ÝÆÊÎöÁ÷³ÌÖУ¬£¬£¬£¬ÆäÉè¼ÆÄ¿µÄÊÇΪÊý¾Ý¿ÆÑ§¼ÒºÍ¿ª·¢ÕßÌṩ¸ßÐÔÄÜ£¬£¬£¬£¬Ò×À©Õ¹ÇÒÒ×ÓÚ°²ÅŵĻúеѧϰ½â¾ö¼Æ»®¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
h2oai/h2o-3 <= 3.46.0.8
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/h2oai/h2o-3/tags/


¾©¹«Íø°²±¸11010802024551ºÅ