zenml
PyPI11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting zenmlpage 1 of 1
- CVE-2024-2032LOWCVSS 3.1EG 3.1✓ Fixed in 0.55.52024-06-06
vulnerable: 0.0.1rc1 ... 0.9.0 (128 versions)
A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creation of multiple users with the same username when requests are sent in parallel. This issue was fixed in version 0.55.5.…
- CVE-2024-2035MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.56.22024-06-06
vulnerable: 0.0.1rc1 ... 0.9.0 (131 versions)
An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, includin…
- CVE-2024-2083CRITICALCVSS 9.9EG 9.9✓ Fixed in 0.55.52024-04-16
vulnerable: 0.0.1rc1 ... 0.9.0 (128 versions)
A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary fil…
- CVE-2024-2171MEDIUMCVSS 4.8EG 4.8✓ Fixed in 0.56.22024-06-06
vulnerable: 0.0.1rc1 ... 0.9.0 (131 versions)
A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the 'logo_url' field. By injecting malicious payloads into this field, an attacker could send harmful messages to other …
- CVE-2024-2213LOWCVSS 3.3EG 3.3✓ Fixed in 0.56.32024-06-06
vulnerable: 0.0.1rc1 ... 0.9.0 (132 versions)
An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current…
- CVE-2024-2260MEDIUMCVSS 4.2EG 4.2✓ Fixed in 0.56.22024-04-16
vulnerable: 0.0.1rc1 ... 0.9.0 (131 versions)
A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated upon logout. This flaw allows an attacker to bypass authentication mechanisms by reusing a victim'…
- CVE-2024-2383MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.56.32024-06-06
vulnerable: 0.0.1rc1 ... 0.9.0 (132 versions)
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to…
- CVE-2024-25723HIGHCVSS 8.8EG 9.0✓ Fixed in 0.44.42024-02-27
vulnerable: 0.44.0, 0.44.1, 0.44.2, 0.44.3
ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with…
- CVE-2024-4311MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.57.0rc22024-11-14
vulnerable: 0.0.1rc1 ... 0.9.0 (135 versions)
zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the current password in the 'Update Password' function, allowing them to take …
- CVE-2024-4680HIGHCVSS 8.8EG 3.92024-06-08
vulnerable: 0.0.1rc1 ... 0.9.0 (133 versions)
A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session IDs due to insufficient session expiration. Specifically, the session does not expire after a password change, enabling an attack…
- CVE-2024-5062MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.58.02024-06-30
vulnerable: 0.0.1rc1 ... 0.9.0 (138 versions)
A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization of input during web page generation, specifically within the survey redirect para…
Check whether zenml is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for zenml CVEs against the assets you own.
Start Free Scan →