Cyber Resilience

CVE-2023-6017

H2O

Public PoC
Published
16 November 2023
Modified
21 November 2024
CVSS Score v3.1 7.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score 0.0086 55th percentile
Risk Priority 54 floored blend · peak EPSS

Summary

CVE-2023-6017 is a high-severity an unspecified weakness vulnerability in H2O H2O. Its CVSS base score is 7.1 (High).

Operationally, ranked in the top 45% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

This vulnerability is AI-related — categorised as Other AI Platforms; in the Supply Chain and Deployment risk domain.

EU & UK References

Vulnerability Data

H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.

CWE(s)

AI Security AnalysisAI

AI Category
Other AI Platforms
Risk Domain
Supply Chain and Deployment
OWASP Top 10 for LLMs 2025
None mapped
Classification Reason
H2O is an AI/ML platform (H2O.ai's machine learning engine), and the vulnerability was reported on a bug bounty platform specifically for AI/ML (huntr.com), confirming AI relevance. The issue involves a reference to a deleted S3 bucket in H2O, fitting 'Other Platforms' as it doesn't match more specific categories like Deep Learning Frameworks or NLP.

Related Threats

CVEs Like This One

CVE-2024-1456Same product: H2O H2O
CVE-2024-5550Same product: H2O H2O
CVE-2024-5979Same product: H2O H2O
CVE-2024-45758Same product: H2O H2O
CVE-2023-6016Same product: H2O H2O
CVE-2024-6863Same product: H2O H2O
CVE-2026-8751Same product: H2O H2O
CVE-2026-8750Same product: H2O H2O
CVE-2024-10549Same product: H2O H2O
CVE-2025-10768Same product: H2O H2O

Affected Assets

h2o
h2o
all versions

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References