CVE-2023-6021: Ray Log File Local File Include

7.5 CVSS

Description

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

Classification

CVE ID: CVE-2023-6021

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

Affected Products

Vendor: ray-project

Product: ray-project/ray

Nuclei Template

http/cves/2023/CVE-2023-6021.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.6% (probability of being exploited)

EPSS Percentile: 78.54% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://huntr.com/bounties/5039c045-f986-4cbc-81ac-370fe4b0d3f8

Timeline