References https://nvd.nist.gov/vuln/detail/CVE-2023-48022 https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023 https://www.anyscale.com/blog/update-on-ray-cve-2023-48022-new-verification-tooling-available https://bishopfox.com/blog/ray-versions-2-6-3-2-8-0 https://avd.aliyun.com/detail?id=AVD-2023-48022 https://github.com/advisories/GHSA-6wgj-66m2-xxp2 https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild https://docs.ray.io/en/latest/ray-security/index.html https://avd.aliyun.com/detail?id=AVD-2024-57000 https://thehackernews.com/2024/03/critical-unpatched-ray-ai-platform.html
Related VulnerabilitiesPoCCVE-2023-48022: Anyscale Ray - Remote Code ExecutionPoCCVE-2023-48023: Anyscale Ray 2.6.3 and 2.8.0 - Server-Side Request ForgeryAnyscale Ray CVE-2023-48022 远程代码执行漏洞Anyscale Ray CVE-2023-48022 远程代码执行漏洞(恶意文件上传)Anyscale Ray CVE-2023-48023 服务端请求伪造漏洞