CVE-2023-6020 is a Local File Inclusion (LFI) vulnerability in the Ray framework's /static/ directory, allowing unauthenticated attackers to read arbitrary files on the server. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low complexity, potentially leading to significant information disclosure. The high EPSS score and FAUCET Risk Score of 99/100 indicate a high likelihood of exploitation. Active exploitation has been reported in the wild, with exploit modules available in Metasploit and Nuclei, and significant community discussion and media coverage highlighting its impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ray_project:ray:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.