CVE-2024-9362
Directory Traversal in polyaxon/polyaxon
Record summary
CVE-2024-9362 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retrieve directory information and file contents from the server without proper authorization, leading to sensitive information disclosure. The issue enables access to system directories such as `/etc`, potentially resulting in significant security risks.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
polyaxon/polyaxonBrowse polyaxon / polyaxon/polyaxon | CVE List | Through latest | affected |
Nuclei templates
1ProjectDiscoveryHIGHPolyaxon - Unauthenticated Directory TraversalCVSS 7.5
Polyaxon latest version contains a path traversal caused by insufficient validation in directory access, letting unauthenticated attackers retrieve directory information and file contents, exploit requires no authentication.
Impact
Attackers can access sensitive system directories and files, leading to information disclosure and potential further exploitation.
Remediation
Update to the latest version with patched validation mechanisms.
Source: ProjectDiscovery