PT-2025-12278 · Polyaxon · Polyaxon
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-9363
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Polyaxon version latest
Description
The issue concerns an unauthorized file deletion vulnerability that can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as
polyaxon.sock, causing the API container to exit unexpectedly. This disrupts related services and prevents the system from functioning normally, without requiring authentication or UUID parameters.Recommendations
For the latest version of Polyaxon, consider restricting access to critical containers and files, such as
polyaxon.sock, to minimize the risk of exploitation. As a temporary workaround, implement additional monitoring and backup procedures to quickly recover from potential disruptions caused by unauthorized file deletion.Fix
DoS
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Polyaxon