An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for unauthorized account takeover by bypassing the standard password change verification process. The issue was fixed in version 0.56.3.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-06-06T18:19:26.553Z

Updated: 2024-06-07T12:49:58.358Z

Reserved: 2024-03-06T08:29:15.083Z


Link: CVE-2024-2213

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-06T19:15:53.890

Modified: 2024-06-07T14:56:05.647


Link: CVE-2024-2213

JSON object: View

cve-icon Redhat Information

No data.

CWE