DIRAC 是一种中间件,即用于分布式计算的软件框架。在 8.0.79、9.0.22 和 9.1.10 版本之前,DataManagementSystem/Service/FileCatalogHandler.py 中的 方法会将由经过身份验证的调用方控制的 值传递给 DatasetManager.py 中的 。在该方法中, 被直接拼接(插值)到 FC_MetaDatasets 的 SQL 查询中,而未使用参数化查询,从而存在 SQL 注入风险。 攻击者可以通过构造恶意的 控制返回的 值,该值随后被传入 Pytho
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45579 | 9.9 CRITICAL | DIRAC: RCE in RequestManager due to eval on untrusted input |
| CVE-2026-61668 | 8.1 HIGH | DIRAC: Pilot code downloaded over unverified HTTPS connection |
No comments yet