PT-2024-23126 · Dirac · Dirac
Highfstagnipu
·
Published
2024-04-09
·
Updated
2026-01-05
·
CVE-2024-29905
CVSS v3.1
8.1
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
DIRAC versions prior to 8.0.41
Description
DIRAC is a software framework for distributed computing. During the proxy generation process, such as when using
dirac-proxy-init, unauthorized users on the same machine can gain read access to the proxy. This allows the user to perform any action possible with the original proxy. The vulnerability exists for a short period, specifically a sub-millisecond time frame, during the generation process.Recommendations
For versions prior to 8.0.41, update to version 8.0.41 to resolve the issue.
As a temporary workaround, setting the
X509 USER PROXY environment variable to a path inside a directory only readable to the current user avoids the potential risk. After the file has been written, it can be safely copied to the standard location (/tmp/x509up uNNNN).Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dirac