CVE-2023-6020: Ray Static File Local File Include
Published Nov 16, 2023
·Updated
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
Affected Software
2 affected componentsFixes available
pip/ray<2.8.1
2.8.1
Ray Project Ray
Event History
Nov 16, 2023
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionSeverityWeakness
Advisory Published
09:30 PM
Mar 26, 2024
News Published
via BleepingComputer·06:51 PM
News Published
via BleepingComputer·06:52 PM
Mar 27, 2024
News Published
via The Register·08:40 PM
News Published
via The Register·08:43 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2023-6020?
CVE-2023-6020 is a vulnerability in Ray's /static/ directory that allows attackers to read any file on the server without authentication.
2
How severe is CVE-2023-6020?
CVE-2023-6020 has a severity level of 9.3 (critical).
3
Which software is affected by CVE-2023-6020?
Ray Project Ray is affected by CVE-2023-6020.
4
How can an attacker exploit CVE-2023-6020?
An attacker can exploit CVE-2023-6020 by accessing the /static/ directory in Ray and reading any file on the server without authentication.
5
Is there a fix for CVE-2023-6020?
There is currently no fix available for CVE-2023-6020, but it is recommended to update Ray and apply any security patches or mitigations provided by the vendor.