Insufficient Session Expiration in zenml-io/zenml
Published Jun 8, 2024
2.0
LOWCVSS 4.0
EPSS 0.41%
Description
A vulnerability in zenml-io/zenml version 0.56.3 allows attackers to reuse old session credentials or session IDs due to insufficient session expiration. Specifically, the session does not expire after a password change, enabling an attacker to maintain access to a compromised account without the victim's ability to revoke this access. This issue was observed in a self-hosted ZenML deployment via Docker, where after changing the password from one browser, the session remained active and usable in another browser without requiring re-authentication.
Affected products
-
Affected
- ≥ unspecified, ≤ latest
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Zenml-IO | Zenml-Io/zenml | unknown | Affected
|
-
Affected
- 0.56.3
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1999 Advisory
- https://github.com/advisories/GHSA-99hm-86h7-gr3g Advisory
- https://huntr.com/bounties/c88f6bd2-490d-4930-98dd-03651b20230a ExploitIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2024-4680
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1999 | Advisory | |
| https://github.com/advisories/GHSA-99hm-86h7-gr3g | Advisory | |
| https://huntr.com/bounties/c88f6bd2-490d-4930-98dd-03651b20230a | ExploitIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-4680 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub