Vulnerabilities > CVE-2023-6019 - Unspecified vulnerability in RAY Project RAY

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
ray-project
critical

Summary

A command injection exists in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication.

Vulnerable Configurations

Part Description Count
Application
Ray_Project
1