Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | H2O-3 JDBC ²ÎÊýÈÆ¹ýÒý·¢·´ÐòÁл¯ RCE |
CVE ID | CVE-2025-6544 |
Îó²îÀàÐÍ | ·´ÐòÁл¯ | ·¢Ã÷ʱ¼ä | 2025-09-23 |
Îó²îÆÀ·Ö | 9.8 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
H2O-3ÊÇÓÉH2O.ai¿ª·¢µÄ¿ªÔ´ÂþÑÜʽ»úеѧϰƽ̨£¬£¬£¬£¬£¬Ö§³Ö´ó¹æÄ£Êý¾Ý´¦Öóͷ£Ó뽨ģ¡£¡£¡£¡£¡£¡£¡£ËüÌṩÁËÆÕ±éµÄËã·¨£¬£¬£¬£¬£¬°üÀ¨·ÖÀ࣬£¬£¬£¬£¬»Ø¹é£¬£¬£¬£¬£¬¾ÛÀ࣬£¬£¬£¬£¬Òì³£¼ì²âºÍÉî¶Èѧϰ£¬£¬£¬£¬£¬Äܹ»ÔÚ´óÊý¾ÝÇéÐÎϸßЧÔËÐС£¡£¡£¡£¡£¡£¡£H2O-3Ö§³Ö¶àÖÖ±à³Ì½Ó¿Ú£¬£¬£¬£¬£¬Èçpython£¬£¬£¬£¬£¬R£¬£¬£¬£¬£¬ScalaºÍJAVA£¬£¬£¬£¬£¬Í¬Ê±ÓëSpark£¬£¬£¬£¬£¬HadoopµÈÉú̬ϵͳ¼æÈÝ£¬£¬£¬£¬£¬Àû±ã¼¯³Éµ½ÆóÒµµÄÊý¾ÝÆÊÎöÁ÷³ÌÖУ¬£¬£¬£¬£¬ÆäÉè¼ÆÄ¿µÄÊÇΪÊý¾Ý¿ÆÑ§¼ÒºÍ¿ª·¢ÕßÌṩ¸ßÐÔÄÜ£¬£¬£¬£¬£¬Ò×À©Õ¹ÇÒÒ×ÓÚ°²ÅŵĻúеѧϰ½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£
2025Äê9ÔÂ23ÈÕ£¬£¬£¬£¬£¬°ÙÀÖ²©¼¯ÍÅVSRC¼à²âµ½h2oai/h2o-3ÖеÄÒ»´¦ÑÏÖØÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹ÌØÊâµÄJDBC connection_url£¨¶Ô¼üÃûË«ÖØURL±àÂë²¢²åÈë¿Õ¸ñµÈ¼¼ÇÉ£©Èƹý²ÎÊýÆ¥ÅäÓë²¹¶¡Ð£Ñ飬£¬£¬£¬£¬×¢Èë¿É¿ØµÄJDBC²ÎÊý£¬£¬£¬£¬£¬ÓëαÔìµÄMySQLЧÀͽ»»¥ºóʵÏÖí§ÒâϵͳÎļþ¶ÁÈ¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»½øÒ»²½Á¬Ïµ¿É´¥·¢µÄ·´ÐòÁл¯Á´£¬£¬£¬£¬£¬Ôò¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£Îó²îÆÀ·Ö9.8£¬£¬£¬£¬£¬Îó²î¼¶±ðÑÏÖØ¡£¡£¡£¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
h2oai/h2o-3 <= 3.46.0.8
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
ÒÑÐû²¼ÐÞ¸´°æ±¾£¬£¬£¬£¬£¬ÇëÉý¼¶µ½H2O-3 >= 3.46.0.8¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/h2oai/h2o-3/tags/
3.2 ÔÝʱ²½·¥
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔÌϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://nvd.nist.gov/vuln/detail/CVE-2025-6544/https://huntr.com/bounties/53f35a0f-d644-4f82-93aa-89fe7e0aed40