Skip to content
ZenMLGHSA-6h3f-43vq-53hj

Directory traversal in zenml

Critical9.9CVE-2024-2083 · Published Apr 16, 2024 · updated May 12, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
zenml
PyPI
< 0.55.50.55.5
Details and references

A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary file content, bypassing intended access restrictions. The vulnerability arises due to the lack of validation for directory traversal patterns, allowing attackers to access files outside of the restricted directory.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-29
Also known as
CVE-2024-2083, PYSEC-2024-247

More ZenML advisories

All ZenML
DateAdvisory
Apr 162024zenml Session Fixation vulnerability
CVE-2024-2260Medium4.2fixed in 0.56.2
Feb 272024ZenML Server Remote Privilege Escalation Vulnerability
CVE-2024-25723High6.5fixed in 0.42.2, 0.43.1, 0.44.4, 0.46.7
Jun 62024Improper authorization in zenml
CVE-2024-2035Medium6.5fixed in 0.56.2
Jun 62024Race condition in zenml
CVE-2024-2032Low3.1fixed in 0.55.5
Jun 62024Improper authentication in zenml
CVE-2024-2213Low3.3fixed in 0.56.3
Jun 62024Clickjacking in zenml
CVE-2024-2383Medium4.3fixed in 0.56.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.