Main
Vulnerability Database
Exploits
ID:9932 - Exploit for Missing Authorization in Ray - CVE-2023-48022
ID:9932 - Exploit for Missing Authorization in Ray - CVE-2023-48022
Published: June 7, 2024
Vulnerability identifier: #VU87915
Vulnerability risk: High
CVE-ID: CVE-2023-48022
CWE-ID: CWE-862
Exploitation vector: Remote access
Vulnerable software:
Ray
Ray
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to execute arbitrary OS commands on the system.
The vulnerability exists due to missing authorization within the the job submission API. A remote user with access to the API endpoint can execute arbitrary OS commands on the system.
Remediation
Install updates from vendor's website.