CVE-2024-2035
Improper authorization in zenml
Description
An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, including changing the `active` status of user accounts to false, effectively deactivating them. This issue affects version 0.55.3 and was fixed in version 0.56.2. The impact of this vulnerability is significant as it allows for the deactivation of admin accounts, potentially disrupting the functionality and security of the application.
How to fix CVE-2024-2035
To remediate CVE-2024-2035, upgrade the affected package to a fixed version below.
- —upgrade to 0.56.2 or later
- —upgrade to b95f083efffa56831cd41d8ed536aeb0b6038fa3 or later
Is CVE-2024-2035 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.56.2
- from 0, < b95f083efffa56831cd41d8ed536aeb0b6038fa3, < b95f083efffa56831cd41d8ed536aeb0b6038fa3 | from 0, < 0.56.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |