dirac@9.1.7

DIRAC is an interware, meaning a software framework for distributed computing.

  • latest version

    9.1.15

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    9 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the dirac package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Eval Injection

    DIRAC is an interware, meaning a software framework for distributed computing.

    Affected versions of this package are vulnerable to Eval Injection in the checkDataset process. An attacker can execute arbitrary code on the server by injecting malicious input into the database query, which is subsequently evaluated. This can lead to full system compromise, including access to sensitive configuration files, database credentials, and stored authentication tokens. If local logging is enabled, an attacker may also remove traces of their activity from the logs.

    How to fix Eval Injection?

    Upgrade DIRAC to version 8.0.79, 9.0.22, 9.1.10 or higher.

    [,8.0.79)[8.1.0a1,9.0.22)[9.1.0,9.1.10)
    • H
    Access Control Bypass

    DIRAC is an interware, meaning a software framework for distributed computing.

    Affected versions of this package are vulnerable to Access Control Bypass via the setPilotStatus function and related database operations. An attacker can modify or access unauthorized database records by supplying specially crafted parameters that are not properly escaped, and can manage or delete pilot jobs by exploiting insufficient access controls.

    How to fix Access Control Bypass?

    Upgrade DIRAC to version 8.0.79, 9.0.22, 9.1.10 or higher.

    [,8.0.79)[8.1.0a1,9.0.22)[9.1.0,9.1.10)
    • C
    Improper Certificate Validation

    DIRAC is an interware, meaning a software framework for distributed computing.

    Affected versions of this package are vulnerable to Improper Certificate Validation in the process that downloads and executes the second stage pilot script over an unverified HTTPS connection. An attacker can intercept and modify the downloaded code by performing a man-in-the-middle attack, potentially leading to the execution of arbitrary code with elevated privileges. This is only exploitable if an attacker is able to successfully perform a man-in-the-middle attack on the network path between the affected system and the remote server.

    How to fix Improper Certificate Validation?

    Upgrade DIRAC to version 8.0.79, 9.0.22, 9.1.10 or higher.

    [,8.0.79)[8.1.0a1,9.0.22)[9.1.0,9.1.10)
    • H
    Eval Injection

    DIRAC is an interware, meaning a software framework for distributed computing.

    Affected versions of this package are vulnerable to Eval Injection in the export_getRequestCountersWeb function when untrusted input is passed to an eval call. An attacker can execute arbitrary code on the server by supplying specially crafted input that is evaluated in the server context. This enables access to sensitive configuration files, database credentials, and stored authentication tokens, as well as the ability to remove evidence from logs.

    How to fix Eval Injection?

    Upgrade DIRAC to version 8.0.79, 9.0.22, 9.1.10 or higher.

    [,8.0.79)[8.1.0a1,9.0.22)[9.1.0,9.1.10)