PT-2023-8890 · Ray · Ray

Published

2023-08-25

·

Updated

2024-03-27

·

CVE-2023-6021

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ray (affected versions not specified)
Description The issue is related to incorrect restriction of a directory path with limited access in the Ray framework for scaling AI and Python applications. This can be exploited by a remote attacker to read arbitrary files using the filename parameter. The log API endpoint in Ray is also affected, allowing attackers to read any file on the server without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-02554
CVE-2023-6021
GHSA-3PWW-QVR8-6MHP

Affected Products

Ray