CVE-2023-6020
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
- Affected products
- Ray
- Ray Project Ray
- All versions
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 14.5% (96th percentile)
- Weakness
- CWE-862
- NVD status
- Modified
- Published
- 2023-11-16
CVE-2023-6020 at NVD
2 known exploits for CVE-2023-6020
Proof-of-concept code and exploit modules indexed by Sploitus