Security Advisory

CVE-2023-6021

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-11-16 16:11:42
Last updated 2024-11-27 17:07:03
Assigner @huntr_ai
CVSS score 7.5
State PUBLISHED

Description

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023