Ray是ray-project开源的一个用于扩展 AI 和 Python 应用程序的统一框架。 Ray存在安全漏洞,该漏洞源于cpu_profile URL参数存在命令注入漏洞。攻击者可利用该漏洞运行Ray仪表板在系统上执行os命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ray-project | ray-project/ray | unspecified ~ latest | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Ray OS Command Injection RCE(Unauthorized) | https://github.com/FireWolfWang/CVE-2023-6019 | POC Details |
| 2 | None | https://github.com/miguelc49/CVE-2023-6019-2 | POC Details |
| 3 | None | https://github.com/miguelc49/CVE-2023-6019-1 | POC Details |
| 4 | None | https://github.com/miguelc49/CVE-2023-6019-3 | POC Details |
| 5 | Python POC for CVE-2023-6019 taken from https://huntr.com/bounties/d0290f3c-b302-4161-89f2-c13bb28b4cfe | https://github.com/Clydeston/CVE-2023-6019 | POC Details |
| 6 | None | https://github.com/Zohaibkhan1472/cve-2023-6019 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-6021 | 7.5 HIGH | Ray Log File Local File Include |
| CVE-2023-6020 | Ray Static File Local File Include |
No comments yet