EXECUTIVE SUMMARY:
The ShadowRay vulnerability poses a significant threat to organizations using the Ray open-source AI framework, allowing attackers to execute arbitrary code remotely without proper authorization. Despite being disputed, this vulnerability has been actively exploited in the wild, leading to compromises in AI infrastructure across various sectors.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
The ShadowRay vulnerability poses a significant threat to organizations using the Ray open-source AI framework, allowing attackers to execute arbitrary code remotely without proper authorization. Despite being disputed, this vulnerability has been actively exploited in the wild, leading to compromises in AI infrastructure across various sectors.[emaillocker id="1283"]
The ShadowRay vulnerability, identified as CVE-2023-48022, stems from Ray's Jobs API lacking proper authorization, enabling unauthorized users to invoke arbitrary jobs on remote hosts. Exploiting this vulnerability grants attackers access to Ray's dashboard network, where they can execute malicious code without authentication. This issue persists in Ray versions 2.6.3 to 2.8.0, exposing vulnerable systems to remote code execution attacks and various risks. For more information, please refer to the link provided below in references.The lack of authorization in Ray's Jobs API has severe implications, including the compromise of sensitive data such as AI models, datasets, third-party tokens, and production database credentials. Attackers can manipulate AI models, modify customer requests, access databases, escalate privileges, and engage in cryptocurrency mining activities using compromised GPU resources. Additionally, attackers gain persistent access to compromised machines through reverse shells, facilitating ongoing exploitation and further compromise of cloud environments and sensitive data. Despite the dispute surrounding CVE-2023-48022, its active exploitation underscores the critical need for organizations to implement proper security controls and monitor for suspicious activity to mitigate the risks associated with ShadowRay.
The ShadowRay vulnerability presents a clear and present danger to organizations relying on the Ray framework for AI workloads. It is imperative for these organizations to conduct thorough reviews of their environments, enforce proper authorization controls, and enhance monitoring capabilities to detect and respond to potential exploitation attempts. By taking proactive measures, organizations can safeguard their AI infrastructure and minimize the impact of ShadowRay-related risks on their operations and data security.
THREAT PROFILE:

REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/hackers-exploit-ray-framework-flaw-to-breach-servers-hijack-resources/