Use of GET Request Method With Sensitive Query Strings
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication.
A command injection exists in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication.