CVE-2025-62593

Lỗ hổng CVE-2025-62593 là gì?

Dữ liệu gốc

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

Xác minh để tiếp tục phân tích

Bước xác minh ngắn giúp bảo vệ nguồn lỗ hổng và hạn chế việc gọi AI tự động.

Giới thiệu chung

Dữ liệu gốc

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

Sản phẩm và phạm vi ảnh hưởng

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Chi tiết kỹ thuật

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Khả năng khai thác

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Tác động kỹ thuật

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Tác động đến tổ chức

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Cách khắc phục

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Cách phát hiện

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Nguồn (4)
Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan
CyStack VulnScan dashboard