dirac@9.0.0a11 vulnerabilities

DIRAC is an interware, meaning a software framework for distributed computing.

Direct Vulnerabilities

Known vulnerabilities in the dirac package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Improper Authentication

DIRAC is an interware, meaning a software framework for distributed computing.

Affected versions of this package are vulnerable to Improper Authentication due to the improper validation of permissions on cached tokens in TokenManager. A user can obtain a token from the cache, that was requested by another user or agent.

How to fix Improper Authentication?

Upgrade DIRAC to version 8.0.37, 9.0.0a22 or higher.

[8.0.0,8.0.37) [8.1.0a1,9.0.0a22)