Skip to content
ZenMLGHSA-mq73-g4qr-fgcq

Clickjacking in zenml

Medium4.3CVE-2024-2383 · Published Jun 6, 2024 · updated Jan 21, 2025

A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control. The issue was addressed in version 0.56.3.

GitHub advisory

Affected versions

PackageAffectedFixed in
zenml
PyPI
< 0.56.30.56.3
Details and references

More ZenML advisories

All ZenML
Advisory
Improper line feed handling in zenml
Medium4.3Jun 24, 2024
zenml-io/zenml does not expire the session after password reset
Low3.9Jun 8, 2024
Improper authorization in zenml
Medium6.5Jun 6, 2024
Race condition in zenml
Low3.1Jun 6, 2024
Improper authentication in zenml
Low3.3Jun 6, 2024
Cross site scripting in zenml
Low3.4Jun 6, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.