A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the victim's browser. This includes creating projects, model versions, and artifact versions, or changing settings. The impact of this vulnerability includes potential data loss and service disruption.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the victim's browser. This includes creating projects, model versions, and artifact versions, or changing settings. The impact of this vulnerability includes potential data loss and service disruption. | |
Title | Cross-Site Request Forgery (CSRF) in polyaxon/polyaxon | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:43.972Z
Updated: 2025-03-20T18:17:34.295Z
Reserved: 2024-09-30T19:57:32.817Z
Link: CVE-2024-9365

Updated: 2025-03-20T17:48:09.672Z

Status : Received
Published: 2025-03-20T10:15:48.467
Modified: 2025-03-20T10:15:48.467
Link: CVE-2024-9365

No data.