PT-2023-8933 · Anyscale · Anyscale Ray

·

CVE-2023-48022

·

Published

2023-08-28

·

Updated

2026-08-23

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Anyscale Ray versions 2.6.3 and 2.8.0 Anyscale Ray versions prior to 2.52.0
Description Anyscale Ray contains a flaw due to insufficient validation of incoming requests and missing authentication for critical functions. This allows an unauthenticated remote attacker to execute arbitrary code via the job submission API and the Ray dashboard web interface. Approximately 230,000 Ray servers are exposed online, making them targets for the ShadowRay 2.0 campaign. In this campaign, threat actors hijack NVIDIA GPU clusters to create a self-propagating, worm-like botnet used for cryptocurrency mining, distributed denial-of-service (DDoS) attacks, and data theft, including the theft of production database credentials, environment variables, and AI models. The attack typically involves initial access via exposed Ray dashboard ports (default 8265).
Recommendations For versions 2.6.3 and 2.8.0, restrict network access to the Ray dashboard (port 8265) to trusted internal IPs only and ensure it is not exposed to the internet. For versions prior to 2.52.0, enable token authentication to secure the environment. Isolate dashboard endpoints and restrict API access to prevent unauthorized use of the job submission API. Monitor network logs for unauthorized access to the Ray dashboard endpoint and anomalous command execution.

Exploit

Fix

DoS

RCE

Missing Authorization

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02669
CVE-2023-48022
ECHO-DE8F-2AD3-E61D
GHSA-6WGJ-66M2-XXP2
PYSEC-2026-517

Affected Products

Anyscale Ray