REDHAT-BUG-2448440: Path Traversal
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ray Dashboardto a version that resolves this vulnerability.Fixed in 2.8.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2448440?
The severity of REDHAT-BUG-2448440 is high, rated at 7 on the CVSS scale.
What is the risk associated with REDHAT-BUG-2448440?
The risk associated with REDHAT-BUG-2448440 is classified as 33, indicating a significant concern for affected systems.
How do I fix REDHAT-BUG-2448440?
To fix REDHAT-BUG-2448440, upgrade Ray Dashboard to version 2.8.1 or later to mitigate the path traversal vulnerability.
What vulnerability type does REDHAT-BUG-2448440 represent?
REDHAT-BUG-2448440 represents a path traversal vulnerability related to improper validation of user-supplied paths.
What software is affected by REDHAT-BUG-2448440?
Ray Dashboard, specifically versions prior to 2.8.1, is affected by REDHAT-BUG-2448440.