AI for Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2024-2260
Python vulnerability analysis and mitigation

Overview

A session fixation vulnerability (CVE-2024-2260) was discovered in the zenml-io/zenml application, affecting the authentication mechanism. The vulnerability was identified in April 2024 and relates to JWT tokens used for user authentication not being invalidated upon logout (NVD, Huntr).

Technical details

The vulnerability is classified as CWE-384 (Session Fixation) and has been assigned a CVSS v3.0 base score of 4.2 (Medium) with the vector string CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N. The issue stems from the application's failure to properly invalidate JWT tokens after user logout, creating a security weakness in the session management system (NVD).

Impact

The vulnerability allows attackers to bypass authentication mechanisms by reusing a victim's JWT token that wasn't properly invalidated after logout. This could lead to unauthorized access to user accounts and potential exposure of sensitive information (NVD).

Exploitability

The vulnerability requires network access and user interaction to exploit, with high attack complexity as indicated by the CVSS metrics. The attack vector is network-based (AV:N) but requires high complexity (AC:H) to execute successfully (NVD).

Mitigation and workarounds

A fix has been implemented and is available in the zenml-io/zenml repository through commit 68bcb3ba60cba9729c9713a49c39502d40fb945e. Users are advised to update to the latest version of the application to address this vulnerability (GitHub).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61667CRITICAL9.9
  • Python logoPython
  • dirac
NoYesSep 15, 2026
CVE-2026-45579CRITICAL9.9
  • Python logoPython
  • dirac
NoYesSep 15, 2026
CVE-2026-61668HIGH8.1
  • Python logoPython
  • dirac
NoYesSep 15, 2026
CVE-2026-55863MEDIUM5.3
  • Python logoPython
  • motioneye
NoYesSep 15, 2026
CVE-2026-53954MEDIUM4.3
  • Python logoPython
  • bugsink
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management