PT-2024-19499 · Zenml · Zenml

Published

2024-04-15

·

Updated

2025-06-12

·

CVE-2024-2260

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions zenml-io/zenml (affected versions not specified)
Description A session fixation issue exists in the zenml-io/zenml application. The problem arises because JWT tokens used for user authentication are not invalidated upon logout. This allows an attacker to bypass authentication mechanisms by reusing a victim's JWT token.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2024-2260
GHSA-G3R5-72HF-P7P2
PYSEC-2024-254

Affected Products

Zenml