CVE-2026-61668
- EPSS 0.24%
- Veröffentlicht 15.09.2026 17:29:26
- Zuletzt bearbeitet 30.09.2026 17:51:56
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the sec...
CVE-2026-61667
- EPSS 0.65%
- Veröffentlicht 15.09.2026 17:26:16
- Zuletzt bearbeitet 30.09.2026 17:51:56
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets value to...
CVE-2026-45579
- EPSS 0.44%
- Veröffentlicht 15.09.2026 17:23:34
- Zuletzt bearbeitet 30.09.2026 17:51:56
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller...
CVE-2024-29905
- EPSS 0.32%
- Veröffentlicht 09.04.2024 17:16:00
- Zuletzt bearbeitet 05.01.2026 15:51:19
DIRAC is an interware, meaning a software framework for distributed computing. Prior to version 8.0.41, during the proxy generation process (e.g., when using `dirac-proxy-init`), it is possible for unauthorized users on the same machine to gain read ...
CVE-2024-24825
- EPSS 0.53%
- Veröffentlicht 09.02.2024 00:15:08
- Zuletzt bearbeitet 21.11.2024 08:59:47
DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. This may expose resources to unintended parties. This issue has been addressed in release version 8.0.37. Users ...