Unauthorized File Deletion in Polyaxon Platform by Vendor
CVE-2024-9363
7.5HIGH
What is CVE-2024-9363?
An unauthorized file deletion vulnerability was identified in the Polyaxon platform, allowing attackers to delete critical files within containers. This leads to denial of service by causing important components, like the polyaxon.sock file, to be removed, which in turn results in the abrupt termination of the API container. The lack of authentication requirements for this action increases the risk, as attackers can exploit this vulnerability to disrupt essential services without needing to provide UUID parameters.
Affected Version(s)
polyaxon/polyaxon <= unspecified
