Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59qj-jcjv-662j

Опубликовано: 08 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

DIRAC's TokenManager does not check permissions on cached tokens

Impact

Any user could get a token that has been requested by another user/agent

Patches

The vulnerability is fixed in version 8.0.37.

Workarounds

None

References

Пакеты

Наименование

DIRAC

pip
Затронутые версииВерсия исправления

>= 8.0.0, < 8.0.37

8.0.37

Наименование

dirac

pip
Затронутые версииВерсия исправления

< 8.0.37

8.0.37

EPSS

Процентиль: 32%
0.00121
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.1
nvd
почти 2 года назад

DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. This may expose resources to unintended parties. This issue has been addressed in release version 8.0.37. Users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 32%
0.00121
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-200