ZenMLGHSA-vwgf-7f9h-h499
Cross site scripting in zenml
Low3.4CVE-2024-2171 · Published Jun 6, 2024 · updated Jan 21, 2025
A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the 'logo_url' field. By injecting malicious payloads into this field, an attacker could send harmful messages to other users, potentially compromising their accounts. The vulnerability affects version 0.55.3 and was fixed in version 0.56.2. The impact of exploiting this vulnerability could lead to user account compromise.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| zenml PyPI | < 0.56.2 | 0.56.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2024-2171, PYSEC-2024-170
More ZenML advisories
All ZenML| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 242024 | Improper line feed handling in zenml | Medium4.3 | 0.57.1 |
| Jun 82024 | zenml-io/zenml does not expire the session after password reset | Low3.9 | No fix yet |
| Jun 62024 | Improper authorization in zenml | Medium6.5 | 0.56.2 |
| Jun 62024 | Race condition in zenml | Low3.1 | 0.55.5 |
| Jun 62024 | Improper authentication in zenml | Low3.3 | 0.56.3 |
| Jun 62024 | Clickjacking in zenml | Medium4.3 | 0.56.3 |