ZenMLGHSA-j527-v579-m98h
Improper authentication in zenml
Low3.3CVE-2024-2213 · Published Jun 6, 2024 · updated Oct 16, 2025
An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for unauthorized account takeover by bypassing the standard password change verification process. The issue was fixed in version 0.56.3.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| zenml PyPI | < 0.56.3 | 0.56.3 |
Details and references
More ZenML advisories
All ZenML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 242024 | Improper line feed handling in zenml | Medium4.3 | 0.57.1 |
| Jun 82024 | zenml-io/zenml does not expire the session after password reset | Low3.9 | No fix yet |
| Jun 62024 | Improper authorization in zenml | Medium6.5 | 0.56.2 |
| Jun 62024 | Race condition in zenml | Low3.1 | 0.55.5 |
| Jun 62024 | Clickjacking in zenml | Medium4.3 | 0.56.3 |
| Jun 62024 | Cross site scripting in zenml | Low3.4 | 0.56.2 |