Unauthorized File Deletion in Polyaxon Platform by Vendor
CVE-2024-9363

7.5HIGH

Key Information:

Vendor

Polyaxon

Vendor
CVE Published:
20 March 2025

What is CVE-2024-9363?

An unauthorized file deletion vulnerability was identified in the Polyaxon platform, allowing attackers to delete critical files within containers. This leads to denial of service by causing important components, like the polyaxon.sock file, to be removed, which in turn results in the abrupt termination of the API container. The lack of authentication requirements for this action increases the risk, as attackers can exploit this vulnerability to disrupt essential services without needing to provide UUID parameters.

Affected Version(s)

polyaxon/polyaxon <= unspecified

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.