First published: Thu Nov 16 2023(Updated: )
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication.
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ray Project Ray | ||
pip/ray | <=2.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6021 is a vulnerability that allows attackers to read any file on the server without authentication.
CVE-2023-6021 has a severity rating of 9.3 (critical).
CVE-2023-6021 affects Ray Project Ray, allowing attackers to read any file on the server without authentication.
To fix CVE-2023-6021, apply the latest security patches or updates provided by Ray Project Ray.
You can find more information about CVE-2023-6021 at the following reference: [https://huntr.com/bounties/5039c045-f986-4cbc-81ac-370fe4b0d3f8]