ZenMLGHSA-6h3f-43vq-53hj
Directory traversal in zenml
Critical9.9CVE-2024-2083 · Published Apr 16, 2024 · updated May 12, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| zenml PyPI | < 0.55.5 | 0.55.5 |
Details and references
A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary file content, bypassing intended access restrictions. The vulnerability arises due to the lack of validation for directory traversal patterns, allowing attackers to access files outside of the restricted directory.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-29
- Also known as
- CVE-2024-2083, PYSEC-2024-247
More ZenML advisories
All ZenML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 162024 | zenml Session Fixation vulnerability CVE-2024-2260Medium4.2fixed in 0.56.2 | Medium4.2 | 0.56.2 |
| Feb 272024 | ZenML Server Remote Privilege Escalation Vulnerability CVE-2024-25723High6.5fixed in 0.42.2, 0.43.1, 0.44.4, 0.46.7 | High6.5 | 0.42.2, 0.43.1, 0.44.4, 0.46.7 |
| Jun 62024 | Improper authorization in zenml CVE-2024-2035Medium6.5fixed in 0.56.2 | Medium6.5 | 0.56.2 |
| Jun 62024 | Race condition in zenml CVE-2024-2032Low3.1fixed in 0.55.5 | Low3.1 | 0.55.5 |
| Jun 62024 | Improper authentication in zenml CVE-2024-2213Low3.3fixed in 0.56.3 | Low3.3 | 0.56.3 |
| Jun 62024 | Clickjacking in zenml CVE-2024-2383Medium4.3fixed in 0.56.3 | Medium4.3 | 0.56.3 |