原始 OSV JSON{
"id": "GHSA-7xw9-549r-8jrc",
"aliases": [],
"details": "### Details\nA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus:\nhttps://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349\n\nhttps://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117\n\nThis won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries.\n\nFurther to this, the PilotManager access control is only set to \"authenticated\"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job:\nhttps://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118\n\nThis is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions.\n\n### Patched versions:\nhttps://pypi.org/project/DIRAC/8.0.79/\nhttps://pypi.org/project/DIRAC/9.0.22/\nhttps://pypi.org/project/DIRAC/9.1.10/",
"summary": "DIRAC: SQL injection and lack of access control in PilotManager service",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "6"
},
{
"fixed": "8.0.79"
}
]
}
],
"package": {
"name": "DIRAC",
"ecosystem": "PyPI"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "8.1.0a1"
},
{
"fixed": "9.0.22"
}
]
}
],
"package": {
"name": "DIRAC",
"ecosystem": "PyPI"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "9.1.0"
},
{
"fixed": "9.1.10"
}
]
}
],
"package": {
"name": "DIRAC",
"ecosystem": "PyPI"
}
}
],
"modified": "2026-07-13T18:38:13Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"
}
],
"published": "2026-07-13T18:38:13Z",
"references": [
{
"url": "https://github.com/DIRACGrid/DIRAC/security/advisories/GHSA-7xw9-549r-8jrc",
"type": "WEB"
},
{
"url": "https://github.com/DIRACGrid/DIRAC",
"type": "PACKAGE"
},
{
"url": "https://pypi.org/project/DIRAC/8.0.79",
"type": "WEB"
},
{
"url": "https://pypi.org/project/DIRAC/9.0.22",
"type": "WEB"
},
{
"url": "https://pypi.org/project/DIRAC/9.1.10",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2026-07-13T18:38:13Z"
}
}