CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-9363: Unauthorized File Deletion in polyaxon/polyaxon

7.5 CVSS

Description

An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as `polyaxon.sock`, causing the API container to exit unexpectedly. This disrupts related services and prevents the system from functioning normally, without requiring authentication or UUID parameters.

Classification

CVE ID: CVE-2024-9363

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem Types

CWE-23 Relative Path Traversal

Affected Products

Vendor: polyaxon

Product: polyaxon/polyaxon

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.35% (probability of being exploited)

EPSS Percentile: 56.18% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2024-9363
https://huntr.com/bounties/ec7b7e1d-795d-4414-93d5-9df35d2fd391

Timeline