ray: Insertion of Sensitive Information into Log File
Published Mar 6, 2025
5.7
MEDIUMCVSS 4.0
EPSS 0.20%
Description
Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If the redis password is passed as an argument, it will be logged and could potentially leak the password. This is only exploitable if: 1) Logging is enabled; 2) Redis is using password authentication; 3) Those logs are accessible to an attacker, who can reach that redis instance. **Note:** It is recommended that anyone who is running in this configuration should update to the latest version of Ray, then rotate their redis password.
Affected products
- Vendor n/a Product Ray Defaultn/a
- Version 0StatusaffectedConstraints<2.43.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ray | n/a |
|
No data.
No data.
Red Hat Enterprise Linux AI (RHEL AI)
ui-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) | ui-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2025-1979 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2350231 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-6129 Advisory
- https://github.com/advisories/GHSA-w4rh-fgx7-q63m Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/ray/PYSEC-2025-23.yaml
- https://github.com/ray-project/ray/commit/64a2e4010522d60b90c389634f24df77b603d85d
- https://github.com/ray-project/ray/issues/50266
- https://github.com/ray-project/ray/pull/50409
- https://nvd.nist.gov/vuln/detail/CVE-2025-1979
- https://security.snyk.io/vuln/SNYK-PYTHON-RAY-8745212
- https://www.cve.org/CVERecord?id=CVE-2025-1979
Change history (0)
No recorded changes yet.