CVE-2024-45758 | h2oai H2O up to 3.46.0.4 JDBC Connection connection_url deserialization (Nessus ID 213041)
A vulnerability was found in h2oai H2O up to 3.46.0.4 and classified as problematic. Affected by this issue is some unknown functionality of the component JDBC Connection Handler. Such manipulation of the argument connection_url leads to deserialization.
This vulnerability is listed as CVE-2024-45758. The attack must be carried out from within the local network. In addition, an exploit is available.