ZenML是一个可扩展的开源 MLOps 框架,用于创建可移植的、可用于生产的机器学习管道。 ZenML 0.46.7之前版本存在安全漏洞,该漏洞源于/api/v1/users/{user_name_or_id}/activate REST API端点允许根据有效用户名和新密码进行访问。攻击者利用该漏洞可以升级权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/david-botelho-mariano/exploit-CVE-2024-25723 | POC Details |
| 2 | ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body. | https://github.com/projectdiscovery/nuclei-templates/blob/main/passive/cves/2024/CVE-2024-25723.yaml | POC Details |
| 3 | ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-25723.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-22251 | 5.9 MEDIUM | Out-of-bounds read vulnerability |
| CVE-2024-1925 | 5.0 MEDIUM | Ctcms Upsys.php unrestricted upload |
| CVE-2024-25398 | Srelay 安全漏洞 | |
| CVE-2024-27508 | Atheme 安全漏洞 | |
| CVE-2024-27507 | libLAS 安全漏洞 | |
| CVE-2024-27356 | GL.iNet product 安全漏洞 | |
| CVE-2024-26473 | KLiK SocialMediaWebsite 安全漏洞 | |
| CVE-2024-26472 | KLiK SocialMediaWebsite 安全漏洞 | |
| CVE-2024-26471 | iBarn 安全漏洞 | |
| CVE-2024-26470 | FullStackHero WebAPI Boilerplate 安全漏洞 | |
| CVE-2024-26542 | Bonitasoft 跨站脚本漏洞 | |
| CVE-2024-25846 | PrestaShop 安全漏洞 | |
| CVE-2024-25843 | PrestaShop 安全漏洞 | |
| CVE-2024-25841 | PrestaShop 安全漏洞 | |
| CVE-2024-25840 | PrestaShop 安全漏洞 | |
| CVE-2023-41506 | Student Enrollment In PHP 安全漏洞 | |
| CVE-2024-25166 | 71CMS 安全漏洞 | |
| CVE-2024-25400 | Subrion CMS 安全漏洞 | |
| CVE-2024-25399 | Subrion CMS 安全漏洞 | |
| CVE-2024-24323 | Litemall 安全漏洞 |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet