-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from two key failures: 1) Password update logic not triggering session termination (likely in user update functions), and 2) Session management not binding tokens to credential versions. The SQLZenStore's password update method is a prime candidate for the first failure pattern. The session creation logic's lack of password hash validation aligns with the second. Confidence is high for the password update function as this is standard security practice, and medium for session creation as implementation details are inferred from vulnerability behavior.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| zenml | pip | <= 0.56.3 |
Ongoing coverage of React2Shell