CVE-2023-6021 is a Local File Inclusion (LFI) vulnerability in the Ray AI framework's log API endpoint, allowing unauthenticated attackers to read arbitrary files on the server. This critical flaw affects ray_project ray versions prior to 2.8.1+. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low complexity, posing a significant risk of data compromise. Its high EPSS score and FAUCET Risk Score of 99/100 underscore its severe potential impact. While not yet in the KEV catalog, this vulnerability is actively being exploited, as evidenced by multiple media reports detailing server breaches and resource hijacking. Publicly available Nuclei templates exist, and there is substantial community discussion and media coverage surrounding this critical issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ray_project:ray:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.