CVE-2024-2383

CVSS V2 None CVSS V3 None
Description
A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control. The issue was addressed in version 0.56.3.
Overview
  • CVE ID
  • CVE-2024-2383
  • Assigner
  • @huntr_ai
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-06-06T18:18:29.911Z
  • Last Modified Date
  • 2024-06-07T19:39:30.275Z
History
Created Old Value New Value Data Type Notes
2024-06-25 23:26:24 Added to TrackCVE