Unauthenticated Directory Traversal Vulnerability in Polyaxon by Bishop Fox
CVE-2024-9362

7.5HIGH

Key Information:

Vendor

Polyaxon

Vendor
CVE Published:
20 March 2025

What is CVE-2024-9362?

An unauthenticated directory traversal vulnerability in Polyaxon allows malicious actors to access sensitive directories and retrieve file contents without proper authorization. This flaw can lead to potential information exposure, enabling attackers to gain access to critical system directories like /etc. As such, organizations using Polyaxon should take immediate steps to remediate this vulnerability to safeguard against unauthorized access and potential data breaches.

Affected Version(s)

polyaxon/polyaxon <= unspecified

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.