CVE-2024-1456: h2o

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to unauthorized takeover.

Affected products

  • h2o h2o: version 3.45.0.6386 only

Published 2024-04-16. Last modified 2026-06-17.