An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as `polyaxon.sock`, causing the API container to exit unexpectedly. This disrupts related services and prevents the system from functioning normally, without requiring authentication or UUID parameters.
CVE ID: CVE-2024-9363
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor: polyaxon
Product: polyaxon/polyaxon
EPSS Score: 0.35% (probability of being exploited)
EPSS Percentile: 56.18% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)