Thousands of companies remain vulnerable to a remote-code-execution bug in Ray, an open-source AI framework used by Amazon, OpenAI, and others, that is being abused by miscreants in the wild to steal sensitive data and illicitly mine for cryptocurrency. This is according to Oligo Security, which dubbed the unpatched vulnerability ShadowRay. The oversight is tracked as CVE-2023-48022, with a critical 9.8 out of 10 CVSS severity rating. On Tuesday the security shop's Avi Lumelsky, Guy Kaplan, and Gal Elbaz warned that the flaw has been under active exploitation for the past seven months, with criminals using it to compromise medical and video analytics businesses, educational institutes, and others that use the machine-learning software. "Researchers at Oligo Security have observed instances of CVE-2023-48022 being actively exploited in the wild, making the disputed CVE a 'shadow vulnerability' — a CVE that doesn't show up in static scans but can still lead to breaches and significant losses," the trio wrote. Ray is a popular open source project overseen by Anyscale, and is used to develop and scale Python-based applications that incorporate machine-learning workloads. Berenice Flores at Bishop Fox, Sierra Haex, and Protect AI disclosed CVE-2023-48022, which exists because of Ray's lack of authorization in its job submission API, to the project's maintainers last year. They also alerted Anyscale about four other flaws, CVE-2023-6019, CVE-2023-6020, CVE-2023-6021 and CVE-2023-48...
'Thousands' of firms vulnerable to security bug in Ray AI
The Register
·Jessica Lyons
·Published Mar 27, 2024
·Updated
Affected Software
2 affected components
Anyscale Ray=2.6.3
Anyscale Ray=2.8.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a remote-code-execution vulnerability in the Ray AI framework affecting thousands of companies.
2
What security implications are discussed in the article?
The vulnerability allows attackers to steal sensitive data and illicitly mine cryptocurrency.
3
What products or software are affected by the vulnerability?
The affected software is the Ray AI framework from Anyscale, specifically versions 2.6.3 and 2.8.0.
4
Who are some notable users of the Ray framework mentioned in the article?
Notable users of Ray include major companies like Amazon and OpenAI.
5
What action should companies take in response to this bug?
Companies using the vulnerable versions of Ray should patch their software to mitigate the risk of exploitation.