Safety vulnerability ID: 71950
The information on this page was manually curated by our Cybersecurity Intelligence Team.
An improper authorization vulnerability exists in the zenml-io/zenml repository, specifically within the API PUT /api/v1/users/id endpoint. This vulnerability allows any authenticated user to modify the information of other users, including changing the active status of user accounts to false, effectively deactivating them. The impact of this vulnerability is significant as it allows for the deactivation of admin accounts, potentially disrupting the functionality and security of the application.
Latest version: 0.70.0
ZenML: Write production-ready ML code.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application