Loading HuntDB...

GHSA-3pww-qvr8-6mhp

GitHub Security Advisory

Ray Path Traversal vulnerability

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

Affected Packages

PyPI ray
Affected versions: 0 (fixed in 2.8.1)

Related CVEs

Key Information

GHSA ID
GHSA-3pww-qvr8-6mhp
Published
November 16, 2023 6:30 PM
Last Modified
January 9, 2025 11:39 PM
CVSS Score
9.0 /10
Primary Ecosystem
PyPI
Primary Package
ray
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.