Executive brief
DIRAC, a software framework for distributed computing, contains security flaws in its PilotManager service. These flaws allow any authenticated user to view or delete computing jobs belonging to other users. Additionally, a database vulnerability could allow an attacker to manipulate or extract sensitive information from the system's database.
Technical details
The DIRAC PilotManager service suffers from two primary vulnerabilities: SQL injection (CWE-89) and improper access control (CWE-284). Several functions in PilotManagerHandler.py and PilotAgentsDB.py pass user-supplied parameters directly to the database layer without proper escaping or parameter substitution. Furthermore, the access control configuration for PilotManager is set to 'authenticated', which fails to enforce granular permissions, allowing any logged-in user to perform administrative actions like deleting or reading the output of any pilot job. Attackers can exploit these issues via network requests to modify or extract database records. The issues are resolved in versions 8.0.79, 9.0.22, and 9.1.10.
Affected products
- DIRACGrid DIRAC >= 6, < 8.0.79
- DIRACGrid DIRAC >= 8.1.0a1, < 9.0.22
- DIRACGrid DIRAC >= 9.1.0, < 9.1.10
Timeline
- 2026-07-13: advisory
- 2026-07-13: patched