LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023
CVE ID: CVE-2023-6021
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
Vendor: ray-project
Product: ray-project/ray
http/cves/2023/CVE-2023-6021.yaml
EPSS Score: 0.6% (probability of being exploited)
EPSS Percentile: 78.54% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)