CVE-2023-48022: SSRF
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-48022?
CVE-2023-48022 is a vulnerability in Anyscale Ray 2.6.3 and 2.8.0 that allows a remote attacker to execute arbitrary code via the job submission API.
What is the severity of CVE-2023-48022?
The severity of CVE-2023-48022 is critical, with a CVSS score of 9.8.
How can a remote attacker exploit CVE-2023-48022?
A remote attacker can exploit CVE-2023-48022 by leveraging the job submission API to execute arbitrary code.
Which versions of Anyscale Ray are affected by CVE-2023-48022?
Versions 2.6.3 and 2.8.0 of Anyscale Ray are affected by CVE-2023-48022.
Is there a fix available for CVE-2023-48022?
Yes, it is recommended to update to a version of Anyscale Ray that is not affected by CVE-2023-48022.