ray is vulnerable to Improper Access Control
40
Medium Risk
Affected versions of this package bind internal services and management endpoints to 0.0.0.0, possibly exposing Ray’s internal servers, dashboard agent HTTP/GRPC endpoints, and runtime environment agent to remote networks and increasing the risk of unauthorized access or information disclosure. The recent changes restrict bindings to the node IP (and localhost for the dashboard agent HTTP server), preventing remote attackers from reaching those interfaces by default and reducing the attack surface.
You are affected if you are using a version that falls within the vulnerable range.
ray is vulnerable to Improper Access Control in versions 1.0.0 - 2.49.2.
Upgrade the ray library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant