Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

CISA Issues Urgent Alert! Critical Vulnerability in Ray Framework Actively Exploited by Hackers, Poses RCE Risk

CISA has added the critical vulnerability CVE-2023-48022 in the Ray Framework, an AI/ML tool, to its KEV catalog after confirming it is actively exploited by hackers. This vulnerability poses a Remote Code Execution (RCE) risk, and an urgent update to version 2.6.2 is recommended.

Edited by SyncTech Solution Published Source Original source
CISA Issues Urgent Alert! Critical Vulnerability in Ray Framework Actively Exploited by Hackers, Poses RCE Risk

πŸ“Œ Key Takeaways:
- CISA has added the Ray Framework vulnerability CVE-2023-48022 to its Known Exploited Vulnerabilities (KEV) catalog after finding evidence of active exploitation by hackers.
- This vulnerability stems from a Missing Authentication issue in the Ray Dashboard, allowing attackers to achieve Remote Code Execution (RCE).
- Anyscale, the developer, has released a patch in Ray version 2.6.2 and urges users to update their systems as soon as possible to prevent damage.

🚨 CISA, the Cybersecurity and Infrastructure Security Agency of the United States, has issued an urgent warning, officially adding a critical security vulnerability in the Ray Framework to its Known Exploited Vulnerabilities (KEV) catalog. This signifies clear evidence that this vulnerability is currently being exploited by hackers to attack various systems.

What is Ray? 🧐
Ray is an open-source framework developed in Python, designed to facilitate distributed computing for Artificial Intelligence (AI) and Machine Learning (ML) tasks. This makes it highly popular among developers and organizations working with AI.

Vulnerability Details πŸ”“
The vulnerability, identified as CVE-2023-48022, was first discovered and reported by Bishop Fox in November 2023. This issue arises from a flaw in access authentication within the Ray Dashboard. If the Dashboard's port is exposed to the network, an attacker on the same network can send malicious commands to execute arbitrary code on the server, posing a critical risk.

Recommendations and Remediation πŸ›‘οΈ
Anyscale, the company behind Ray's development, has already released a patch to fix this vulnerability in Ray version 2.6.2. CISA has emphasized and urged U.S. federal agencies to apply this patch by June 18, 2024, highlighting the urgency of this issue. General users and organizations should check their current Ray version and update to the latest version immediately to prevent becoming victims.

πŸ’¬ Who among you is using the Ray Framework for AI/ML development? Please check and update immediately!

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.