← Back

CVE-2023-48023

Published: Nov 28, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment

Affected (2)

Products: Anyscale: Ray
1 product
Ray
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Anyscale
Version 2.6.3
Version 2.8.0

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ProductRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductRelease Notes

Timeline

No history available yet.