Ray Log File Local File Include
48Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7.5epss 37%
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
ray-project · ray-project/ray