CVE-2024-2213: Improper Authentication in zenml-io/zenml
An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for unauthorized account takeover by bypassing the standard password change verification process. The issue was fixed in version 0.56.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2213?
CVE-2024-2213 is considered a critical vulnerability due to its potential for unauthorized password changes.
How do I fix CVE-2024-2213?
To fix CVE-2024-2213, upgrade zenml to version 0.56.3 or later.
What versions are affected by CVE-2024-2213?
CVE-2024-2213 affects zenml versions up to and including 0.55.4.
Can CVE-2024-2213 be exploited remotely?
CVE-2024-2213 requires an attacker to have access to an active user session, making it less likely to be exploited remotely.
What impact does CVE-2024-2213 have on users?
CVE-2024-2213 allows an attacker to change a user's account password without knowing the current password, compromising account security.