Record summary

CVE-2024-9362 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retrieve directory information and file contents from the server without proper authorization, leading to sensitive information disclosure. The issue enables access to system directories such as `/etc`, potentially resulting in significant security risks.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough latestaffected

Nuclei templates

1
ProjectDiscoveryHIGHPolyaxon - Unauthenticated Directory TraversalCVSS 7.5

Polyaxon latest version contains a path traversal caused by insufficient validation in directory access, letting unauthenticated attackers retrieve directory information and file contents, exploit requires no authentication.

Impact

Attackers can access sensitive system directories and files, leading to information disclosure and potential further exploitation.

Remediation

Update to the latest version with patched validation mechanisms.

WeaknessesCWE-22
Authorsyunseo
Template tagscvecve2024polyaxonlfitraversalunauth
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
FOFA: title=="Polyaxon"

Source: ProjectDiscovery

References

2