PT-2025-12278 · Polyaxon · Polyaxon

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2024-9363

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Polyaxon version latest
Description The issue concerns an unauthorized file deletion vulnerability that can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as polyaxon.sock, causing the API container to exit unexpectedly. This disrupts related services and prevents the system from functioning normally, without requiring authentication or UUID parameters.
Recommendations For the latest version of Polyaxon, consider restricting access to critical containers and files, such as polyaxon.sock, to minimize the risk of exploitation. As a temporary workaround, implement additional monitoring and backup procedures to quickly recover from potential disruptions caused by unauthorized file deletion.

Fix

DoS

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9363

Affected Products

Polyaxon