🔥 24×7 Proxy Interview Support · Job Support · Profile Engineering | USA • Canada • UK • Europe • Australia

Postmortem · CVE-2023-48022 · Actively Exploited

ShadowRay (CVE-2023-48022) — Ray Job-Submission RCE Postmortem

Ray’s dashboard and job API ship without auth by default. Exposed to a network, that is remote code execution — and it has been exploited at scale.

If you run Ray for distributed training or inference and the dashboard or job-submission API is reachable from an untrusted network, anyone who can reach it can run arbitrary code on your cluster.

ShadowRay (CVE-2023-48022) stems from the fact that Ray’s job-submission API — exposed by default via the Ray Dashboard — performs no authentication and accepts arbitrary Python for execution on cluster nodes. Any attacker with network access can submit malicious jobs that run with the Ray process’s privileges. Security researchers (Oligo) found it actively exploited for cryptojacking and data theft across 200,000+ exposed Ray servers, spanning education, crypto, and biopharma, with a later "ShadowRay 2.0" campaign turning clusters into a self-spreading botnet. The status is notably "disputed": Anyscale states Ray is designed to run only inside a strictly controlled network and that the missing auth is an intentional architectural choice — which makes network isolation your responsibility, not a patch. The record and hardening are below.

What We Offer

Expert Support for Every IT Challenge

From daily job support to emergency production fixes, proxy interview guidance, and interview coaching — we have the expert for your specific need.

Real-Time Kubernetes AI Job Support

Live expert help during your working hours — running LLM inference (vLLM, KServe, Dynamo), agent runtimes and sandboxes, GPU scheduling, autoscaling, RAG pipelines, and daily platform deliverables on your real cluster so you always hit your deadlines.

Production AI Incident Support

On-call firefighting for live incidents — GPU Pods stuck Pending, CUDA/OOMKilled crashes, vLLM out-of-memory, high TTFT, model-loading failures, autoscaling that will not scale, agent loops, MCP authorization errors, and RAG/vector-DB latency — with an engineer on the call.

Interview & Candidate Marketing

Kubernetes AI proxy interview assistance, profile positioning, and candidate marketing for Platform Engineer, AI Infrastructure Engineer, GPU Infrastructure Engineer, MLOps/LLMOps, and SRE roles — real-time interview guidance, recruiter readiness, and profile visibility.

Real Situations

Incident Record

These are the real-world situations our experts resolve every day — for job support and interview assistance.

DATE: CVE assigned late 2023; large-scale active exploitation reported March 2024 (Oligo "ShadowRay"); "ShadowRay 2.0" botnet campaign reported in 2025.
PLATFORM: Ray clusters (KubeRay / RayService on Kubernetes, VMs, or bare metal) with the dashboard/job API network-reachable.
COMPONENT: Ray job-submission API / Ray Dashboard (no authentication by default).
WHAT HAPPENED: The job-submission API accepts and executes arbitrary Python with no authentication; any network-reachable client can run code on cluster nodes.
IMPACT: Remote code execution, cryptojacking, data and credential theft, and lateral movement; 200,000+ exposed servers observed, later weaponised into a botnet.
ROOT CAUSE: By-design lack of authentication on the job API, combined with clusters exposed outside a controlled network — hence the "disputed" CVE status.
MITIGATION: Never expose the Ray dashboard/API to untrusted networks. Enforce network isolation (private subnets, NetworkPolicy), put an authenticating reverse proxy in front, bind to localhost/cluster-internal only, and lock down the KubeRay service type (no public LoadBalancer).
FIX: There is no auth-adding patch (the vendor considers isolation the control); treat hardening as the fix — isolate, authenticate at the proxy/ingress, and monitor for unexpected job submissions.
OPERATIONAL LESSON: "Runs only in a trusted network" is an operational requirement you must enforce. For AI frameworks that assume a trusted perimeter, network isolation and an auth layer are not optional.

Global Reach

Real-time Kubernetes AI infrastructure support for engineers across USA, Canada, UK, Ireland, Germany, Netherlands, Switzerland, Australia, New Zealand, Singapore, UAE, and worldwide.

Available across US, Canada, UK, European, Australian, and Asia-Pacific business hours — and 24/7 for production incidents.

In-house experts — no sub-contracting or outsourcing
24/7 availability for urgent job support and interview needs
Confidential & professional — NDA available on request
Same-day onboarding for most job support and interview cases
Combined job support + proxy interview service available

Ready to Get Expert Help? Talk to Us Now.

Join 1000+ developers who resolved their job challenges and cleared interviews with real-time expert support.

Expert Help Available

Need real-time IT job support or interview help? Our experts are available 24/7 — USA, Canada, UK, Europe & worldwide.

Get Instant HelpCall Now

FAQ

Frequently Asked Questions

Everything you need to know before getting started with job support or interview assistance.

Ask on WhatsApp

The job-submission API accepts and executes arbitrary Python with no authentication; any network-reachable client can run code on cluster nodes. Remote code execution, cryptojacking, data and credential theft, and lateral movement; 200,000+ exposed servers observed, later weaponised into a botnet. You are likely affected if you run Ray job-submission API / Ray Dashboard (no authentication by default). at the versions noted in the record below. We can audit your cluster against this and the wider class of AI-infrastructure risks and tell you precisely where you are exposed.

Fix: There is no auth-adding patch (the vendor considers isolation the control); treat hardening as the fix — isolate, authenticate at the proxy/ingress, and monitor for unexpected job submissions. Mitigation if you cannot patch immediately: Never expose the Ray dashboard/API to untrusted networks. Enforce network isolation (private subnets, NetworkPolicy), put an authenticating reverse proxy in front, bind to localhost/cluster-internal only, and lock down the KubeRay service type (no public LoadBalancer). We help you apply the fix safely in production — staged rollout, verification, and the admission/network guardrails that reduce blast radius for the next issue of this class.

"Runs only in a trusted network" is an operational requirement you must enforce. For AI frameworks that assume a trusted perimeter, network isolation and an auth layer are not optional. This is why we treat the AI-infrastructure supply chain, container runtime, and admission path as security-critical — not just the application layer.

Yes. We run a focused review of your container runtime (NVIDIA Container Toolkit / GPU Operator versions), ingress and admission webhooks, model and image supply chain, agent/tool sandboxing, and RBAC/network policy — mapping each finding to a concrete fix and a guardrail. See our Kubernetes AI security hub.

Both. This page documents a real, publicly disclosed incident with its official source so you can act on it. If you would rather an engineer work it with you — patching safely in production, or auditing for the wider class of risk — that service is available same-day and confidentially.

Official Sources

Oligo Security’s ShadowRay research, the GitHub Security Advisory GHSA-6wgj-66m2-xxp2 (CVE-2023-48022, including the disputed status and Anyscale’s position), and Ray’s own security documentation on running in a controlled network.

Read the GitHub Security Advisory (CVE-2023-48022)

Get Started Today

Exposed to ShadowRay (CVE-2023-48022) or Want a Cluster Security Review?

In-house Kubernetes, GPU, and AI-infrastructure security engineers available same-day — safe production patching, blast-radius review, and hardening against this class of risk. Talk to ProxyTechSupport on WhatsApp now.

Proxy Tech Support provides interview preparation, technical guidance, and job support services. All services are advisory and educational in nature.