Description
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6cxr-8q3m-jwrr | Ray Missing Authorization vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-02T08:21:17.152Z
Reserved: 2023-11-08T09:13:06.312Z
Link: CVE-2023-6020
No data.
Status : Modified
Published: 2023-11-16T21:15:09.443
Modified: 2024-11-21T08:42:59.663
Link: CVE-2023-6020
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA