
Cloud Vulnerability DB
A community-led vulnerabilities database
ZenML Server in the ZenML machine learning package before version 0.46.7 contains a critical security vulnerability (CVE-2024-25723) that allows remote privilege escalation. The vulnerability affects all versions below 0.46.7, except for the patched versions 0.44.4, 0.43.1, and 0.42.2. The vulnerability was disclosed on February 27, 2024 (NVD).
The vulnerability exists in the /api/v1/users/{user_name_or_id}/activate REST API endpoint. The endpoint allows unauthorized access by accepting a valid username along with a new password in the request body, enabling privilege escalation. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).
If exploited, this vulnerability allows attackers to take ownership of ZenML accounts through the user activation feature, potentially leading to unauthorized access and privilege escalation within the system (ZenML Blog).
The vulnerability can be exploited remotely by providing a valid username and a new password through the affected API endpoint. The attack requires low complexity and minimal privileges to execute (NVD).
Users are strongly advised to upgrade to ZenML version 0.46.7 or above, or to one of the patched versions (0.44.4, 0.43.1, 0.42.2). For direct installations, users can upgrade using the command 'pip install "zenml==0.46.7"'. For containerized environments, the ZenML container image or deployment configuration should be updated to use the new version. ZenML Cloud users are automatically protected as the cloud versions have been patched (ZenML Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."