SCA: security update for zenml (GHSA-9x88-4jg8-4vf7)

medium Tenable Self-Hosted Container Security Plugin ID 413543

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the
API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the
information of other users, including changing the `active` status of user accounts to false, effectively
deactivating them. This issue affects version 0.55.3 and was fixed in version 0.56.2. The impact of this
vulnerability is significant as it allows for the deactivation of admin accounts, potentially disrupting
the functionality and security of the application. (CVE-2024-2035)

See Also

https://github.com/advisories/GHSA-9x88-4jg8-4vf7

Plugin Details

Severity: Medium

ID: 413543

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.37

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.7

Temporal Score: 6

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:C/A:C

CVSS Score Source: CVE-2024-2035

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/6/2024

Vulnerability Publication Date: 6/6/2024

Reference Information

CVE: CVE-2024-2035