CVE-2024-25723 is a critical privilege escalation vulnerability affecting ZenML Server in ZenML machine learning package versions prior to 0.46.7, 0.44.4, 0.43.1, and 0.42.2. It allows remote attackers to gain elevated privileges by exploiting an improper authentication flaw in the /api/v1/users/{user_name_or_id}/activate REST API endpoint. With a CVSS score of 8.8 (HIGH), successful exploitation grants high confidentiality, integrity, and availability impacts with low attack complexity and no user interaction required. While there is no evidence of active exploitation or Metasploit/ExploitDB modules, Nuclei templates exist, indicating potential for exploitation, though community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.42.2CPE matchmatch criteria | cpe:2.3:a:zenml:zenml:*:*:*:*:*:*:*:* | ||
>= 0.44.0, < 0.44.4CPE matchmatch criteria | cpe:2.3:a:zenml:zenml:*:*:*:*:*:*:*:* | ||
>= 0.45.0, < 0.46.7CPE matchmatch criteria | cpe:2.3:a:zenml:zenml:*:*:*:*:*:*:*:* | ||
0.43.0CPE matchmatch criteria | cpe:2.3:a:zenml:zenml:0.43.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.