/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-8fp2-j4pf-99hp

Published

Last updated

https://images.chainguard.dev/security/CGA-8fp2-j4pf-99hp
Package

py3.10-vllm-cuda-12.6

Repository

Chainguard

Latest Update
Fixed
Fixed Version

0.8.4-r0

Aliases
  • CVE-2025-1979
  • GHSA-w4rh-fgx7-q63m

Severity

Unknown

Summary

ray vulnerable to Insertion of Sensitive Information into Log File

Description

Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If the redis password is passed as an argument, it will be logged and could potentially leak the password.

This is only exploitable if:

  1. Logging is enabled;

  2. Redis is using password authentication;

  3. Those logs are accessible to an attacker, who can reach that redis instance.

Note:

It is recommended that anyone who is running in this configuration should update to the latest version of Ray, then rotate their redis password.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs