Логотип exploitDog
bind:CVE-2024-2213
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-2213

Количество 2

Количество 2

nvd логотип

CVE-2024-2213

больше 1 года назад

An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for unauthorized account takeover by bypassing the standard password change verification process. The issue was fixed in version 0.56.3.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-j527-v579-m98h

больше 1 года назад

Improper authentication in zenml

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-2213

An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for unauthorized account takeover by bypassing the standard password change verification process. The issue was fixed in version 0.56.3.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-j527-v579-m98h

Improper authentication in zenml

CVSS3: 3.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу