9.1.15
5 years ago
9 days ago
Known vulnerabilities in the dirac package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
DIRAC is an interware, meaning a software framework for distributed computing. Affected versions of this package are vulnerable to Eval Injection in the How to fix Eval Injection? Upgrade | [,8.0.79)[8.1.0a1,9.0.22)[9.1.0,9.1.10) |
DIRAC is an interware, meaning a software framework for distributed computing. Affected versions of this package are vulnerable to Access Control Bypass via the How to fix Access Control Bypass? Upgrade | [,8.0.79)[8.1.0a1,9.0.22)[9.1.0,9.1.10) |
DIRAC is an interware, meaning a software framework for distributed computing. Affected versions of this package are vulnerable to Improper Certificate Validation in the process that downloads and executes the second stage pilot script over an unverified HTTPS connection. An attacker can intercept and modify the downloaded code by performing a man-in-the-middle attack, potentially leading to the execution of arbitrary code with elevated privileges. This is only exploitable if an attacker is able to successfully perform a man-in-the-middle attack on the network path between the affected system and the remote server. How to fix Improper Certificate Validation? Upgrade | [,8.0.79)[8.1.0a1,9.0.22)[9.1.0,9.1.10) |
DIRAC is an interware, meaning a software framework for distributed computing. Affected versions of this package are vulnerable to Eval Injection in the How to fix Eval Injection? Upgrade | [,8.0.79)[8.1.0a1,9.0.22)[9.1.0,9.1.10) |