-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unauthenticated LFI in Ray's /static/ directory. The static file handler in the dashboard's HTTP server would be responsible for serving these files. The CWE-598 (GET-based LFI) and CWE-862 (missing auth) indicate a handler function processing GET requests without authorization or path validation. The 2.8.1 patch notes mention critical fixes to file access controls in the dashboard component, and the vulnerability's mechanics align with improper handling of static file requests.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ray | pip | < 2.8.1 | 2.8.1 |
KEV Misses 88% of Exploited CVEs- Get the report