GHSA-3pww-qvr8-6mhp

Suggest an improvement
Source
https://github.com/advisories/GHSA-3pww-qvr8-6mhp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-3pww-qvr8-6mhp/GHSA-3pww-qvr8-6mhp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3pww-qvr8-6mhp
Aliases
Published
2023-11-16T18:30:31Z
Modified
2026-09-10T03:50:03Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N CVSS Calculator
Summary
Ray Path Traversal vulnerability
Details

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

Database specific
{
    "cwe_ids":  [
        "CWE-22",
        "CWE-29"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-11-27T23:20:39Z",
    "nvd_published_at":  "2023-11-16T17:15:09Z",
    "severity":  "CRITICAL"
}
References

Affected packages

PyPI / ray

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.1

Affected versions

0.*
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.4.0
0.5.0
0.5.2
0.5.3
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.8.0
0.8.1
0.8.2
0.8.3
0.8.4
0.8.5
0.8.6
0.8.7
1.*
1.0.0
1.0.1
1.1.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.7.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.10.0
1.11.0
1.11.1
1.12.0
1.12.1
1.13.0
2.*
2.0.0
2.0.1
2.1.0
2.2.0
2.3.0rc0
2.3.0
2.3.1
2.4.0
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0rc0
2.7.0
2.7.1
2.7.2
2.8.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-3pww-qvr8-6mhp/GHSA-3pww-qvr8-6mhp.json"