Summary:
The open-source framework Ray, a crucial tool for scaling AI and ML workloads, is currently facing a significant security threat due to three unpatched vulnerabilities recently disclosed by researchers. These vulnerabilities could potentially grant attackers access to the operating system across all nodes in a Ray cluster, allowing them to execute remote code and escalate privileges. Despite being reported to, the company managing Ray, In security vendor Protect AI, the vulnerabilities have yet to be addressed. The vulnerabilities are inconsequential Ray is not intended for use outside strictly controlled network environments, as outlined in their documentation. However, given Ray's widespread use by major entities like OpenAI, Spotify, Uber, Netflix, Instacart, and its integration into Amazon's AWS, these vulnerabilities pose a serious threat to organizations relying on Ray for scalable AI and ML applications.[/subscribe_to_unlock_form]
Summary:
The open-source framework Ray, a crucial tool for scaling AI and ML workloads, is currently facing a significant security threat due to three unpatched vulnerabilities recently disclosed by researchers. These vulnerabilities could potentially grant attackers access to the operating system across all nodes in a Ray cluster, allowing them to execute remote code and escalate privileges. Despite being reported to, the company managing Ray, In security vendor Protect AI, the vulnerabilities have yet to be addressed. The vulnerabilities are inconsequential Ray is not intended for use outside strictly controlled network environments, as outlined in their documentation. However, given Ray's widespread use by major entities like OpenAI, Spotify, Uber, Netflix, Instacart, and its integration into Amazon's AWS, these vulnerabilities pose a serious threat to organizations relying on Ray for scalable AI and ML applications.[emaillocker id="1283"]
The vulnerabilities identified by involve flaws in authentication and input validation in Ray Dashboard, Ray Client, and potentially other components, affecting versions 2.6.3 and 2.8.0. Exploiting these flaws could allow attackers to access data, scripts, or files stored in a Ray cluster, and even retrieve highly privileged AWS IAM credentials for privilege escalation. The three specific vulnerabilities, assigned CVE-2023-48023, CVE-2023-48022, and CVE-2023-6021, are associated with remote code execution, server-side request forgery, and insecure input validation, respectively. highlights the ease of exploiting these vulnerabilities, requiring only remote access to vulnerable component ports from the Internet or local networks.
Recommendations:
References:
The following reports contain further technical details:
[/emaillocker]