QID 996078
Date Published: 2023-11-28
QID 996078: Python (Pip) Security Update for ray (GHSA-h3xg-wv58-5p43)
A command injection exists in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-h3xg-wv58-5p43 for updates and patch information.
Vendor References
- GHSA-h3xg-wv58-5p43 -
github.com/advisories/GHSA-h3xg-wv58-5p43
CVEs related to QID 996078
Software Advisories
| Advisory ID | Software | Component | Link |
|---|