CVE-2024-1456: h2o
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthorized takeover.
Affected products
- h2o h2o: version 3.45.0.6386 only
Published 2024-04-16. Last modified 2026-06-17.