{"id":"GHSA-7xw9-549r-8jrc","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7xw9-549r-8jrc","summary":"DIRAC: SQL injection and lack of access control in PilotManager service","details":"### Details\nA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus:\nhttps://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349\n\nhttps://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117\n\nThis won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries.\n\nFurther to this, the PilotManager access control is only set to \"authenticated\"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job:\nhttps://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118\n\nThis is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions.\n\n### Patched versions:\nhttps://pypi.org/project/DIRAC/8.0.79/\nhttps://pypi.org/project/DIRAC/9.0.22/\nhttps://pypi.org/project/DIRAC/9.1.10/","published":"2026-07-13T18:38:13Z","modified":"2026-07-13T18:46:54.887739752Z","cvss":{"score":8.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"dirac","fixedVersion":"8.0.79"},{"ecosystem":"PyPI","name":"dirac","fixedVersion":"9.0.22"},{"ecosystem":"PyPI","name":"dirac","fixedVersion":"9.1.10"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/DIRACGrid/DIRAC/security/advisories/GHSA-7xw9-549r-8jrc"},{"type":"PACKAGE","url":"https://github.com/DIRACGrid/DIRAC"},{"type":"WEB","url":"https://pypi.org/project/DIRAC/8.0.79"},{"type":"WEB","url":"https://pypi.org/project/DIRAC/9.0.22"},{"type":"WEB","url":"https://pypi.org/project/DIRAC/9.1.10"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T18:46:54.887739752Z"}}