Record summary

EIP currently links 1 repository PoC and 1 Nuclei template to CVE-2024-25723.

Description

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body. These are also patched versions: 0.44.4, 0.43.1, and 0.42.2.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 26, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore 0.46.7affected
GitHub AdvisoryBefore 0.42.2 · Fixed in 0.42.2affected
0.43.0affected
0.43.0 to < 0.43.1 · Fixed in 0.43.1affected
0.45.0 to < 0.46.7 · Fixed in 0.46.7affected
0.44.0 to < 0.44.4 · Fixed in 0.44.4affected

Proofs of concept

1

Repository PoCs

GitHubdavid-botelho-mariano/exploit-CVE-2024-25723Repository PoCby david-botelho-marianoStars: 4Not analyzed3 files

5.4 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALZenML ZenML Server - Improper Authentication

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body.

Impact

Successful exploitation could lead to unauthorized access to sensitive data.

Remediation

Implement proper authentication mechanisms and ensure access controls are correctly configured.

AuthorsDavid Botelho Mariano
Template tagscvecve2024passiveauth-bypasszenmlvuln
Shodan: http.favicon.hash:-2028554187
FOFA: body="ZenML"

Source: ProjectDiscovery

References

6