Anyscale Ray 2.6.3 and 2.8.0 contain a remote code execution vulnerability due to insecure job submission API, allowing attackers to execute arbitrary code remotely if they have network access to the Ray Dashboard API.
id: CVE-2023-48022
info:
name: Anyscale Ray - Remote Code Execution
author: riteshs4hu
severi
...