PT-2024-19019 · Zenml · Zenml

CVE-2024-2171

·

Published

2024-06-06

·

Updated

2024-10-11

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions zenml-io/zenml versions 0.55.3 through 0.55.3
Description A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the logo url field. By injecting malicious payloads into this field, an attacker could send harmful messages to other users, potentially compromising their accounts. The impact of exploiting this vulnerability could lead to user account compromise.
Recommendations For version 0.55.3, update to version 0.56.2 to resolve the issue. As a temporary workaround, consider restricting access to the logo url field until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2171
GHSA-VWGF-7F9H-H499
PYSEC-2024-170

Affected Products

Zenml