Zenml

Zenml

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.37%
  • Veröffentlicht 06.06.2024 19:15:53
  • Zuletzt bearbeitet 21.11.2024 09:09:10

A stored Cross-Site Scripting (XSS) vulnerability was identified in the zenml-io/zenml repository, specifically within the 'logo_url' field. By injecting malicious payloads into this field, an attacker could send harmful messages to other users, pote...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 06.06.2024 19:15:53
  • Zuletzt bearbeitet 15.10.2025 13:15:42

An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, including changing ...

  • EPSS 0.29%
  • Veröffentlicht 06.06.2024 19:15:53
  • Zuletzt bearbeitet 21.11.2024 09:08:53

A race condition vulnerability exists in zenml-io/zenml versions up to and including 0.55.3, which allows for the creation of multiple users with the same username when requests are sent in parallel. This issue was fixed in version 0.55.5. The vulner...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 16.04.2024 00:15:11
  • Zuletzt bearbeitet 12.06.2025 23:48:17

A session fixation vulnerability exists in the zenml-io/zenml application, where JWT tokens used for user authentication are not invalidated upon logout. This flaw allows an attacker to bypass authentication mechanisms by reusing a victim's JWT token...

Exploit
  • EPSS 37.49%
  • Veröffentlicht 16.04.2024 00:15:11
  • Zuletzt bearbeitet 12.05.2025 13:12:08

A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary file content, ...

  • EPSS 0.71%
  • Veröffentlicht 14.03.2024 19:15:50
  • Zuletzt bearbeitet 05.05.2025 17:53:36

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

  • EPSS 70.58%
  • Veröffentlicht 27.02.2024 15:15:07
  • Zuletzt bearbeitet 12.05.2025 13:29:53

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new pass...