Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | H2O-3 JDBC ²ÎÊýÈÆ¹ýÒý·¢·´ÐòÁл¯ RCE |
CVE ID | CVE-2025-6544 |
Îó²îÀàÐÍ | ·´ÐòÁл¯ | ·¢Ã÷ʱ¼ä | 2025-09-23 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
H2O-3ÊÇÓÉH2O.ai¿ª·¢µÄ¿ªÔ´ÂþÑÜʽ»úеѧϰƽ̨£¬£¬£¬£¬£¬£¬Ö§³Ö´ó¹æÄ£Êý¾Ý´¦Öóͷ£Ó뽨ģ¡£¡£¡£¡£¡£¡£¡£ËüÌṩÁËÆÕ±éµÄËã·¨£¬£¬£¬£¬£¬£¬°üÀ¨·ÖÀ࣬£¬£¬£¬£¬£¬»Ø¹é£¬£¬£¬£¬£¬£¬¾ÛÀ࣬£¬£¬£¬£¬£¬Òì³£¼ì²âºÍÉî¶Èѧϰ£¬£¬£¬£¬£¬£¬Äܹ»ÔÚ´óÊý¾ÝÇéÐÎϸßЧÔËÐС£¡£¡£¡£¡£¡£¡£H2O-3Ö§³Ö¶àÖÖ±à³Ì½Ó¿Ú£¬£¬£¬£¬£¬£¬Èçpython£¬£¬£¬£¬£¬£¬R£¬£¬£¬£¬£¬£¬ScalaºÍJAVA£¬£¬£¬£¬£¬£¬Í¬Ê±ÓëSpark£¬£¬£¬£¬£¬£¬HadoopµÈÉú̬ϵͳ¼æÈÝ£¬£¬£¬£¬£¬£¬Àû±ã¼¯³Éµ½ÆóÒµµÄÊý¾ÝÆÊÎöÁ÷³ÌÖУ¬£¬£¬£¬£¬£¬ÆäÉè¼ÆÄ¿µÄÊÇΪÊý¾Ý¿ÆÑ§¼ÒºÍ¿ª·¢ÕßÌṩ¸ßÐÔÄÜ£¬£¬£¬£¬£¬£¬Ò×À©Õ¹ÇÒÒ×ÓÚ°²ÅŵĻúеѧϰ½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£
2025Äê9ÔÂ23ÈÕ£¬£¬£¬£¬£¬£¬918²©ÌìÌü¯ÍÅVSRC¼à²âµ½h2oai/h2o-3ÖеÄÒ»´¦ÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹ÌØÊâµÄJDBC connection_url£¨¶Ô¼üÃûË«ÖØURL±àÂë²¢²åÈë¿Õ¸ñµÈ¼¼ÇÉ£©Èƹý²ÎÊýÆ¥ÅäÓë²¹¶¡Ð£Ñ飬£¬£¬£¬£¬£¬×¢Èë¿É¿ØµÄJDBC²ÎÊý£¬£¬£¬£¬£¬£¬ÓëαÔìµÄMySQLЧÀͽ»»¥ºóʵÏÖí§ÒâϵͳÎļþ¶ÁÈ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»½øÒ»²½Á¬Ïµ¿É´¥·¢µÄ·´ÐòÁл¯Á´£¬£¬£¬£¬£¬£¬Ôò¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£Îó²îÆÀ·Ö9.8£¬£¬£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
h2oai/h2o-3 <= 3.46.0.8
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÒÑÐû²¼ÐÞ¸´°æ±¾£¬£¬£¬£¬£¬£¬ÇëÉý¼¶µ½H2O-3 >= 3.46.0.8¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/h2oai/h2o-3/tags/
3.2 ÔÝʱ²½·¥
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2025-6544/https://huntr.com/bounties/53f35a0f-d644-4f82-93aa-89fe7e0aed40