ZeroHour
Exploit-DBpublished ()ingested

[webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion

mediumExploit / PoCimportance 40
AI summary · glm-5.3

Public exploit released for directory traversal and local file inclusion in Ray 2.56.0, the widely used distributed ML framework.

Exploit-DB entry 52635 publishes a web application exploit targeting Ray 2.56.0, the distributed computing framework from Anyscale commonly used for ML workloads. The PoC demonstrates a directory traversal and local file inclusion condition, allowing attackers to read files outside the intended path on an exposed Ray instance. Ray dashboard instances exposed to the internet could leak sensitive files such as credentials and configuration.

  • Directory traversal and LFI in Ray 2.56.0
  • Public PoC published on Exploit-DB
  • Internet-exposed Ray dashboards could leak sensitive files
Full article

Ray 2.56.0 - Directory Traversal & Local File Inclusion

This source does not provide full text. Read it at exploit-db.com.