Cross-Site Request Forgery Vulnerability in Polyaxon by Polyaxon
CVE-2024-9365

6.5MEDIUM

Key Information:

Vendor

Polyaxon

Vendor
CVE Published:
20 March 2025

What is CVE-2024-9365?

A Cross-Site Request Forgery (CSRF) vulnerability affecting Polyaxon version 2.4.0 enables attackers to execute unauthorized actions within the victim's browser. This includes creating and modifying projects, model versions, and artifact versions, as well as altering critical settings. The potential ramifications involve significant data loss and disruptions to service continuity. It is essential for users to be aware of this vulnerability to safeguard their data and maintain system integrity.

Affected Version(s)

polyaxon/polyaxon <= unspecified

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.