PT-2023-8933 · Anyscale · Anyscale Ray
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Anyscale Ray versions 2.6.3 and 2.8.0
Anyscale Ray versions prior to 2.52.0
Description
Anyscale Ray contains a flaw due to insufficient validation of incoming requests and missing authentication for critical functions. This allows an unauthenticated remote attacker to execute arbitrary code via the job submission API and the Ray dashboard web interface. Approximately 230,000 Ray servers are exposed online, making them targets for the ShadowRay 2.0 campaign. In this campaign, threat actors hijack NVIDIA GPU clusters to create a self-propagating, worm-like botnet used for cryptocurrency mining, distributed denial-of-service (DDoS) attacks, and data theft, including the theft of production database credentials, environment variables, and AI models. The attack typically involves initial access via exposed Ray dashboard ports (default 8265).
Recommendations
For versions 2.6.3 and 2.8.0, restrict network access to the Ray dashboard (port 8265) to trusted internal IPs only and ensure it is not exposed to the internet.
For versions prior to 2.52.0, enable token authentication to secure the environment.
Isolate dashboard endpoints and restrict API access to prevent unauthorized use of the job submission API.
Monitor network logs for unauthorized access to the Ray dashboard endpoint and anomalous command execution.
Exploit
Fix
DoS
RCE
Missing Authorization
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anyscale Ray