louie.rocks

Home

❯

Boxes

❯

PG CVE 2023 6019

PG-CVE-2023-6019

Apr 01, 20241 min read

  • ray-dashboard
  • cve-2023-6019

Find open ports (22, 9000, 35537, 36499, 39181, 40241, 43355, 44217, 44227, 45545, 52365, 56188, 59882, 61770)

Pasted image 20240729060112

Find port 9000 is running Ray Dashboard

Pasted image 20240729060503

The docs button also led to a guide on Ray Dashboard:

Pasted image 20240729060603

Find and execute an exploit for Ray Dashboard

This GitHub submitted issue suggests there is an unauthenticated RCE for versions of the Ray Dashboard ⇐ 2.6.3. I’m unsure of the version installed on this instance, but it’s worth looking into.

I obtain a reverse shell as root using the POC from this GitHub repo.

Pasted image 20240729061040

Pasted image 20240729061101

Obtain proof.txt

Pasted image 20240729061456


Created with Quartz v4.5.0 © 2025

  • GitHub
  • Discord Community