← back
CVE-2024-2083criticalCWE-29

Directory Traversal in zenml-io/zenml

60Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.9epss 37%
from disclosure to weapon691 days
Published on NVDApr 16
1st PoC+691d
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary file content, bypassing intended access restrictions. The vulnerability arises due to the lack of validation for directory traversal patterns, allowing attackers to access files outside of the restricted directory.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.