CVE-2023-48023: SSRF
Anyscale Ray 2.6.3 and 2.8.0 allows /logproxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-48023?
CVE-2023-48023 is a vulnerability in Anyscale Ray 2.6.3 and 2.8.0 that allows Server-Side Request Forgery (SSRF) through the /log_proxy endpoint.
What is the severity of CVE-2023-48023?
The severity of CVE-2023-48023 is critical with a severity value of 9.1.
What software versions are affected by CVE-2023-48023?
Anyscale Ray versions 2.6.3 and 2.8.0 are affected by CVE-2023-48023.
What is the vendor's position on CVE-2023-48023?
The vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment.
How can I fix CVE-2023-48023?
There is currently no official fix available for CVE-2023-48023. It is recommended to follow the vendor's guidance and use Ray only in a strictly controlled network environment.