Cern

Rucio

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 06.05.2026 17:21:24
  • Zuletzt bearbeitet 11.05.2026 15:00:58

### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgres_query()`. This allows any authenticated Rucio user to execute arbitrary SQL against the P...

  • EPSS 0.28%
  • Veröffentlicht 06.05.2026 17:16:22
  • Zuletzt bearbeitet 11.05.2026 15:07:20

A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (`GET /dids/<scope>/dids/search`). On Oracle deployments att...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 25.02.2026 20:23:48
  • Zuletzt bearbeitet 27.02.2026 19:24:03

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerabilit...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 25.02.2026 20:23:48
  • Zuletzt bearbeitet 27.02.2026 19:24:13

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerabilit...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 25.02.2026 20:23:47
  • Zuletzt bearbeitet 27.02.2026 19:23:40

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerabilit...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 25.02.2026 20:23:47
  • Zuletzt bearbeitet 27.02.2026 19:23:54

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerabilit...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 25.02.2026 19:28:35
  • Zuletzt bearbeitet 27.02.2026 17:35:41

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Prior to versions 35.8.3, 38.5.4, and 39.3.1, the WebUI login endpoint returns distinct error mess...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 25.02.2026 18:57:28
  • Zuletzt bearbeitet 27.02.2026 15:43:26

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. A reflected Cross-site Scripting vulnerability was located in versions prior to 35.8.3, 38.5.4, an...