CVE-2023-6038 is a Local File Inclusion (LFI) vulnerability in the h2o-3 REST API, specifically affecting h2o-3 version 3.40.0.4. This allows unauthenticated attackers to read arbitrary files on the server. With a CVSS score of 7.5 (HIGH), it requires no user interaction and has a high impact on confidentiality. While not currently in CISA's KEV catalog, exploit templates are available for tools like Nuclei, and it has garnered significant community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:h2o:h2o:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.