GHSA-xg2h-7cxj-3gvh

Suggest an improvement
Source
https://github.com/advisories/GHSA-xg2h-7cxj-3gvh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xg2h-7cxj-3gvh
Aliases
  • CVE-2024-57000
Downstream
CGA (2)
Withdrawn
2025-02-14T21:30:14Z
Published
2025-02-12T00:32:17Z
Modified
2026-09-10T03:50:06Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Withdrawn Advisory: Command injection in Ray
Details

Withdrawn Advisory

This advisory is a duplicate of GHSA-6wgj-66m2-xxp2 / CVE-2023-48022.

Original Description

An issue in Anyscale Inc Ray between v.2.9.3 and v.2.40.0 allows a remote attacker to execute arbitrary code via a crafted script.

Database specific
{
    "cwe_ids":  [
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-02-12T19:33:10Z",
    "nvd_published_at":  "2025-02-11T23:15:09Z",
    "severity":  "CRITICAL"
}
References

Affected packages

PyPI / ray

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.9.3
Last Affected
2.40.0

Affected versions

2.*
2.9.3
2.10.0
2.11.0
2.12.0
2.20.0
2.21.0
2.22.0
2.23.0
2.24.0
2.30.0
2.31.0
2.32.0rc0
2.32.0
2.33.0
2.34.0
2.35.0
2.36.0
2.36.1
2.37.0
2.38.0
2.39.0
2.40.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json"