© 2025-2026 PySpect
First version without a known vulnerability: 8.0.79
DIRAC: SQL injection and lack of access control in PilotManager service
Fixed in: 8.0.79, 9.0.22, 9.1.10
DIRAC: Pilot code downloaded over unverified HTTPS connection
Fixed in: 8.0.79, 9.0.22, 9.1.10
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
Fixed in: 8.0.79, 9.0.22, 9.1.10
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
Fixed in: 8.0.79, 9.0.22, 9.1.10
DIRAC: Unauthorized users can read proxy contents during generation
Fixed in: 8.0.41
DIRAC's TokenManager does not check permissions on cached tokens
Fixed in: 8.0.37, f9ddab755b9a69acb85e14d2db851d8ac0c9648c