PT-2024-19019 · Zenml · Zenml

Published

2024-06-06

·

Updated

2024-10-11

·

CVE-2024-2171

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions zenml-io/zenml versions 0.55.3 through 0.55.3
Description A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the logo url field. By injecting malicious payloads into this field, an attacker could send harmful messages to other users, potentially compromising their accounts. The impact of exploiting this vulnerability could lead to user account compromise.
Recommendations For version 0.55.3, update to version 0.56.2 to resolve the issue. As a temporary workaround, consider restricting access to the logo url field until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2171
GHSA-VWGF-7F9H-H499
PYSEC-2024-170

Affected Products

Zenml