B
今週中
Ray 2.56.0 の /logs API において、ディレクトリトラバーサルおよびローカルファイルインクルージョン (LFI) の脆弱性
📌 一言でいうと
Ray 2.56.0 の /logs API において、ディレクトリトラバーサルおよびローカルファイルインクルージョン (LFI) の脆弱性が報告されました。攻撃者は細工したグロブフィルタを送信することで、意図されたログディレクトリ外のファイルにリモートから認証なしでアクセスすることが可能です。現在、修正案が提案されており、メンテナーによるレビューが行われています。
🔍該当判定
- AIや機械学習の分散処理フレームワークである「Ray」を導入している
- Rayのバージョンが「2.56.0」である
- Rayの管理画面やAPI(特に/logs API)を外部ネットワークからアクセス可能な状態で公開している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. Ray の最新のセキュリティアップデートを確認し、修正パッチがリリースされ次第適用すること。 2. 修正が適用されるまで、外部から /logs API へのアクセスを制限または遮断すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Ray 2.56.0 ディレクトリトラバーサル脆弱性への対応について
お疲れさまです。Ray 2.56.0 に関する脆弱性の情報共有です。
■ 概要
Ray 2.56.0 の /logs API にて、認証なしで任意のファイルを読み取ることができるディレクトリトラバーサル/LFIの脆弱性が発見されました。攻撃者が細工したリクエストを送信することで、システム上の機密ファイルにアクセスされる恐れがあります。
■ 影響範囲
- 対象製品: Ray
- 対象バージョン: 2.56.0
■ 対応手順
1. 外部から Ray の API (特に /logs エンドポイント) へのアクセスが制限されているか確認してください。
2. 上流での修正 (GH PR #64701) がマージされ、正式なアップデートがリリースされ次第、速やかに適用してください。
■ 参考情報
- GH Issue: https://github.com/ray-project/ray/issues/45751
- GH Pull Request: https://github.com/ray-project/ray/pull/64701
対応優先度: 高
対応期限: アップデートリリース後速やかに
お疲れさまです。Ray 2.56.0 に関する脆弱性の情報共有です。
■ 概要
Ray 2.56.0 の /logs API にて、認証なしで任意のファイルを読み取ることができるディレクトリトラバーサル/LFIの脆弱性が発見されました。攻撃者が細工したリクエストを送信することで、システム上の機密ファイルにアクセスされる恐れがあります。
■ 影響範囲
- 対象製品: Ray
- 対象バージョン: 2.56.0
■ 対応手順
1. 外部から Ray の API (特に /logs エンドポイント) へのアクセスが制限されているか確認してください。
2. 上流での修正 (GH PR #64701) がマージされ、正式なアップデートがリリースされ次第、速やかに適用してください。
■ 参考情報
- GH Issue: https://github.com/ray-project/ray/issues/45751
- GH Pull Request: https://github.com/ray-project/ray/pull/64701
対応優先度: 高
対応期限: アップデートリリース後速やかに
Subject: [Security Advisory] Directory Traversal Vulnerability in Ray 2.56.0
Dear IT/Security Team,
We are sharing information regarding a vulnerability identified in Ray 2.56.0.
■ Overview
A directory traversal and Local File Inclusion (LFI) vulnerability exists in the /logs API of Ray 2.56.0. This allows a remote unauthenticated attacker to access files outside the intended log directory by using a crafted glob filter.
■ Scope
- Product: Ray
- Version: 2.56.0
■ Mitigation Steps
1. Verify that access to Ray's API (specifically the /logs endpoint) is restricted from untrusted networks.
2. Monitor the upstream project for the official release of the fix (currently under review in GH PR #64701) and apply the update immediately upon release.
■ Reference
- GH Issue: https://github.com/ray-project/ray/issues/45751
- GH Pull Request: https://github.com/ray-project/ray/pull/64701
Priority: High
Deadline: Immediately upon patch release
Dear IT/Security Team,
We are sharing information regarding a vulnerability identified in Ray 2.56.0.
■ Overview
A directory traversal and Local File Inclusion (LFI) vulnerability exists in the /logs API of Ray 2.56.0. This allows a remote unauthenticated attacker to access files outside the intended log directory by using a crafted glob filter.
■ Scope
- Product: Ray
- Version: 2.56.0
■ Mitigation Steps
1. Verify that access to Ray's API (specifically the /logs endpoint) is restricted from untrusted networks.
2. Monitor the upstream project for the official release of the fix (currently under review in GH PR #64701) and apply the update immediately upon release.
■ Reference
- GH Issue: https://github.com/ray-project/ray/issues/45751
- GH Pull Request: https://github.com/ray-project/ray/pull/64701
Priority: High
Deadline: Immediately upon patch release