PT-2024-20109 · Zenml Io · Zenml

Published

2024-06-06

·

Updated

2024-10-11

·

CVE-2024-2383

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions zenml-io/zenml versions up to and including 0.55.5
Description A clickjacking issue exists due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control.
Recommendations For versions up to and including 0.55.5, update to version 0.56.3 to resolve the issue. As a temporary workaround, consider restricting access to the application UI to minimize the risk of exploitation.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2024-2383
GHSA-MQ73-G4QR-FGCQ
PYSEC-2024-194

Affected Products

Zenml