CVE-2024-2383
MEDIUMzenml <= 0.55.5 - Clickjacking via Missing X-Frame-Options Header
Title source: llmDescription
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control. The issue was addressed in version 0.56.3.
References (2)
Core 2
Core References
Exploit, Issue Tracking, Patch, Third Party Advisory
https://huntr.com/bounties/22d26f5a-c0ae-4344-aa7d-08ff5ada3963
Scores
CVSS v3
6.1
EPSS
0.0035
EPSS Percentile
27.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1021
Status
published
Products (2)
pypi/zenml
0 - 0.56.3PyPI
zenml/zenml
< 0.56.3
Published
Jun 06, 2024
Tracked Since
Feb 18, 2026