{"id":"CVE-2024-2383","aliases":["GHSA-mq73-g4qr-fgcq","PYSEC-2024-194"],"url":"https://o3.security/vulnerability/CVE-2024-2383","summary":"Clickjacking Vulnerability in zenml-io/zenml","details":"A clickjacking vulnerability exists in zenml-io/zenml versions up to and including 0.55.5 due to the application's failure to set appropriate X-Frame-Options or Content-Security-Policy HTTP headers. This vulnerability allows an attacker to embed the application UI within an iframe on a malicious page, potentially leading to unauthorized actions by tricking users into interacting with the interface under the attacker's control. The issue was addressed in version 0.56.3.","published":"2024-06-06T18:18:29.911Z","modified":"2026-08-12T03:51:15.932640258Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":{"score":0.00357,"percentile":0.28989,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"zenml","fixedVersion":"0.56.3"}],"fix":{"url":"https://github.com/zenml-io/zenml/commit/f863fde1269bc355951f8cfc826c0244d88ad5e9","label":"zenml-io/zenml@f863fde"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/22d26f5a-c0ae-4344-aa7d-08ff5ada3963"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2383.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-2383"},{"type":"FIX","url":"https://github.com/zenml-io/zenml/commit/f863fde1269bc355951f8cfc826c0244d88ad5e9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.932640258Z"}}