PT-2025-12277 · Polyaxon · Polyaxon
Published
2025-03-20
·
Updated
2026-06-07
·
CVE-2024-9362
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Polyaxon version latest
Description
A directory traversal vulnerability exists, allowing an attacker to retrieve directory information and file contents from the server without proper authorization. This leads to sensitive information disclosure and enables access to system directories such as /etc, potentially resulting in significant security risks.
Recommendations
For the latest version, update to a version that includes a fix for this issue, as no specific workaround is provided for this version.
As a temporary workaround, consider restricting access to sensitive directories and files to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Polyaxon