Skip to main content
CRITICAL

CVE-2024-2083

CVSS v3

9.9

CRITICAL

EPSS Score

37.5 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary file content, bypassing intended access restrictions. The vulnerability arises due to the lack of validation for directory traversal patterns, allowing attackers to access files outside of the restricted directory.

Technical details

Published
2024-04-16

Frequently asked questions

What is CVE-2024-2083?

A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary file content, bypassing intended access restrictions. The vulnerability arises due to the lack of validation for directory traversal patterns, allowing attackers to access files outside of the restricted directory.

Is CVE-2024-2083 actively exploited?

Active exploitation of CVE-2024-2083 has not been confirmed. Its EPSS score was 37.5% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2024-2083?

CVE-2024-2083 has a CVSS v3 base score of 9.9 (CRITICAL severity).

Is CVE-2024-2083 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key