ZenMLGHSA-mq73-g4qr-fgcq
Clickjacking in zenml
Medium4.3CVE-2024-2383 · Published Jun 6, 2024 · updated Jan 21, 2025
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control. The issue was addressed in version 0.56.3.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| zenml PyPI | < 0.56.3 | 0.56.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1021
- Also known as
- CVE-2024-2383, PYSEC-2024-194
More ZenML advisories
All ZenML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 242024 | Improper line feed handling in zenml | Medium4.3 | 0.57.1 |
| Jun 82024 | zenml-io/zenml does not expire the session after password reset | Low3.9 | No fix yet |
| Jun 62024 | Improper authorization in zenml | Medium6.5 | 0.56.2 |
| Jun 62024 | Race condition in zenml | Low3.1 | 0.55.5 |
| Jun 62024 | Improper authentication in zenml | Low3.3 | 0.56.3 |
| Jun 62024 | Cross site scripting in zenml | Low3.4 | 0.56.2 |