Safety vulnerability ID: 71950
The information on this page was manually curated by our Cybersecurity Intelligence Team.
An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, including changing the active status of user accounts to false, effectively deactivating them. The impact of this vulnerability is significant as it allows for the deactivation of admin accounts, potentially disrupting the functionality and security of the application.
Latest version: 0.91.0
ZenML: MLOps for Reliable AI: from Classical AI to Agents.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application