PoC Index

CVE-2023-48023

CRITICAL 9.1EPSS 35.3%

Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment

CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
35.30% chance of exploitation in the next 30 days, 98th percentile
Nuclei
critical
Published
2023-11-28
Updated
2024-10-10

Nuclei templates (1)

References

Related