2024 Anyscale Ray — ShadowRay CVE-2023-48022, unauthenticated RCE
Data compromised
Sensitive datasets; AI models; third-party tokens; compute resources
Technical writeup
Critical vulnerability in Ray AI framework (CVE-2023-48022, CVSS 9.8). Jobs API lacked authentication; unauthenticated attackers could execute arbitrary code. Dubbed ShadowRay; exploited since late 2023. Thousands of Ray servers compromised globally across education, crypto, biopharma. Attackers could access datasets, models, third-party tokens.
Root cause
Missing authentication on Jobs API; design flaw