SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Ray Project Ray Dashboard browser-based remote code execution attempt
This rule looks for a set of characteristic strings associated with a malicious JavaScript job submission script in the HTTP response body on the Ray Dashboard port. Successful exploitation enables an attacker‑controlled browser to submit a crafted job to the Ray Dashboard, leading to remote code execution on the host running the service.
This rule fires on attempts to deliver a browser-based remote code execution payload targeting Ray Dashboard clients.
Attacks/Scans seen in the wild
Known false positives, with the described conditions
Legitimate or custom JavaScript that constructs a Ray /api/jobs POST request and explicitly sets User-Agent in the same ordered structure could potentially match.
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Execution::User Execution::Malicious File
MITRE::ATT&CK Framework::Enterprise::Initial Access::Drive-by Compromise
Rule Categories::Server::Web Applications
Vulnerability::Severity::Critical
Vulnerability::Severity::High
Command Injection
Command Injection attacks target applications that allow unsafe user-supplied input. Attackers transmit this input via forms, cookies, HTTP headers, etc. and exploit the applications permissions to execute system commands without injecting code.
CVE-2025-62593 |
Loading description
|