CVE-2024-2383

MEDIUM

zenml-io/zenml <0.55.5 - CSRF

Title source: llm
STIX 2.1

Description

A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control. The issue was addressed in version 0.56.3.

Scores

CVSS v3 6.1
EPSS 0.0006
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1021
Status published
Products (2)
pypi/zenml 0 - 0.56.3PyPI
zenml/zenml < 0.56.3
Published Jun 06, 2024
Tracked Since Feb 18, 2026