Ray 2.6.3 与 2.8.0 版本安全通告
bishopfox.com | 博客 | #vulnerability-disclosure | #ai-infrastructure | #ssrf | #input-validation | #missing-authentication | #ray | #anyscale
摘要
Bishop Fox 披露 Ray 2.6.3/2.8.0 的三个漏洞——缺失认证、SSRF 与不安全输入校验,可使未授权用户获取集群节点的操作系统权限;Ray 2.8.1 修复其中两个,官方建议将集群部署于隔离网络。
- 发布时间
- 收录时间
Skip to content