漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Missing Authorization in get_deployed_stack Endpoint in zenml-io/zenml
Vulnerability Description
In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all users and tenants. This includes stack component details, service connector information, and user IDs of stack owners. The vulnerability arises from two issues: missing endpoint-level RBAC checks and the use of a server-side `Client()` that bypasses the RBAC enforcement layer by directly accessing the database through `SqlZenStore`. This exposes sensitive information such as infrastructure topology, service connector details, stack ownership, and deployment metadata, potentially enabling cross-tenant reconnaissance and further attacks in multi-tenant ZenML Pro/Cloud deployments.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
ZenML 授权问题漏洞
Vulnerability Description
ZenML是ZenML公司开源的一个可扩展的开源 MLOps 框架,用于创建可移植的、可用于生产的机器学习管道。 ZenML 0.94.2版本存在授权问题漏洞,该漏洞源于`GET /api/v1/stack-deployment/stack`端点缺少RBAC授权检查,可能导致任何经过身份验证的用户枚举所有用户和租户的已部署堆栈、堆栈组件详细信息、服务连接器信息以及堆栈拥有者用户ID,从而暴露基础设施拓扑、堆栈所有权、部署元数据等敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A