S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-6021 Scanner

CVE-2023-6021 scanner - Local File Inclusion (LFI) vulnerability in ray-project/ray

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-6021
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ray-project/rayby ray-project
unspecified
Updated Aug 22, 2026View on NVD →
Detail

Ray is an open-source distributed computing framework that is used to simplify the process of building and running distributed applications. It enables developers to easily scale their applications across multiple machines and clusters by providing a simple API for writing parallel and distributed tasks. The project is maintained by a team called ‘Anyscale’ and is widely popular in the Python community.

However, a critical vulnerability was recently detected in Ray's log API endpoint, the CVE-2023-6021. This vulnerability allows attackers to execute a Local File Inclusion attack which exposes confidential information to the attacker. In simple terms, an attacker may access sensitive information on the server without the requirement of any authentication. This kind of attack can lead to disastrous consequences for the integrity of the system, including data breaches and unauthorized access.

As a result of this vulnerability, attackers may have access to valuable data and resources, which can lead to significant financial and intellectual losses. This kind of attack is particularly harmful for organizations that rely heavily on sensitive data and resources, such as financial institutions, government agencies, and healthcare organizations. It is also important to note that the severity of the damage caused by this vulnerability rests on the context of the data and the resources being accessed.

At S4E, we take cyber-security seriously, and our pro features are designed to help individuals and organizations safeguard their digital resources. We provide regular updates on security vulnerabilities that could affect your digital assets, and our advanced threat intelligence technology allows you to stay ahead of cyber threats. By using our platform, you can have peace of mind knowing that you are protected from the latest security threats.  So, subscribe to us today and stay ahead of security vulnerabilities.

 

REFERENCES

Solution Advice

Fortunately, there are precautions that can be taken to minimize the risk of CVE-2023-6021 attacks. Here are some of the notable security measures:

  • Updating to the latest version of Ray
  • Limiting the use of the affected components of Ray, in this case, the log API endpoint
  • Monitoring of network traffic to detect and prevent the attack
  • Implementing a Web Application Firewall (WAF)
  • Setting up network segmentation

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.