DIRAC 是一种 interware(中间件),即为分布式计算提供支持的软件框架。在 8.0.79、9.0.22 和 9.1.10 版本之前, 中的 使用 来下载第二阶段的 归档文件,且未进行 TLS 证书验证,同时也通过这条未经验证的通道下载对应的校验和(checksum)。 攻击者若能够通过 DNS 或路由操纵来重定向或截获网格站点(grid site)的网络流量,就可以同时替换可执行的 pilot 代码及其校验和,从而让任意代码在 pilot 上下文中运行,并获得对 pilot 代理凭据的访问权限。 修复后
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45579 | 9.9 CRITICAL | DIRAC: RCE in RequestManager due to eval on untrusted input |
| CVE-2026-61667 | 9.9 CRITICAL | DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval |
No comments yet