Low severityNVD Advisory· Published Jun 6, 2024· Updated Oct 21, 2025
Improper Authentication in zenml-io/zenml
CVE-2024-2213
Description
An issue was discovered in zenml-io/zenml versions up to and including 0.55.4. Due to improper authentication mechanisms, an attacker with access to an active user session can change the account password without needing to know the current password. This vulnerability allows for unauthorized account takeover by bypassing the standard password change verification process. The issue was fixed in version 0.56.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
zenmlPyPI | < 0.56.3 | 0.56.3 |
Affected products
2- Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-j527-v579-m98hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-2213ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/zenml/PYSEC-2024-193.yamlghsaWEB
- github.com/zenml-io/zenml/commit/58cb3d987372c91eb605853c35325701733337c2ghsaWEB
- huntr.com/bounties/8f5534ac-fd08-4b8b-8c2e-35949aa36e48ghsaWEB
News mentions
0No linked articles in our index yet.