CVE-2024-2383
Clickjacking in zenml
4.3
MEDIUM
CVSS 3.1
EPSS 0.06%
Description
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control. The issue was addressed in version 0.56.3.
How to fix CVE-2024-2383
To remediate CVE-2024-2383, upgrade the affected package to a fixed version below.
- —upgrade to 0.56.3 or later
- —upgrade to f863fde1269bc355951f8cfc826c0244d88ad5e9 or later
Is CVE-2024-2383 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.56.3
- from 0, < f863fde1269bc355951f8cfc826c0244d88ad5e9, < f863fde1269bc355951f8cfc826c0244d88ad5e9 | from 0, < 0.56.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |