CVE-2023-6020
HIGH NUCLEIRay < 2.8.1 - Unauthenticated Local File Inclusion via Static Directory
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-6020.
PoCs published by byt3bl33d3r <[email protected]>, danmcinerney <[email protected]>, Takahiro Yokoyama, including Metasploit module auxiliary/gather/ray_lfi_cve_2023_6020.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits a local file inclusion (LFI) vulnerability in Ray before 2.8.1, allowing arbitrary file reads via path traversal. It includes functionality to check for vulnerability and read specified files.
Description
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
Exploits (1)
This Metasploit module exploits a local file inclusion (LFI) vulnerability in Ray before 2.8.1, allowing arbitrary file reads via path traversal. It includes functionality to check for vulnerability and read specified files.
Nuclei Templates (1)
http.favicon.hash:463802404 || http.html:"ray dashboard"
body="ray dashboard" || icon_hash=463802404
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N