Junglewise Threat Intelligence
CVE-2024-24825: PYSEC-2024-125 - DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. Th
CVE-2024-24825 · Severity: low · CVSS 3.1 · Published 2024-02-09
Technologies: DIRAC (PyPI). Vendors: PyPI.
Executive brief
DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. This may expose resources to unintended parties. This issue has been addressed in release version 8.0.37. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Related threats
- DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagem
- DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementS
- DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestMana
- PYSEC-2026-1295 - DIRAC: Unauthorized users can read proxy contents during generation