{"id":"CVE-2024-24825","aliases":["GHSA-59qj-jcjv-662j","PYSEC-2024-125"],"title":"DIRAC's TokenManager does not check permissions on cached tokens","summary":"DIRAC's TokenManager does not check permissions on cached tokens","severity":"critical","cvss":9.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","vendor":"dirac","product":"dirac","ecosystem":"pip","affected":["dirac >= 8.0.0, < 8.0.37","dirac < 8.0.37"],"patched":["dirac 8.0.37","dirac 8.0.37"],"published":"2024-02-08","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:09.929133236Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-59qj-jcjv-662j","references":[{"url":"https://github.com/DIRACGrid/DIRAC/security/advisories/GHSA-59qj-jcjv-662j"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24825"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/9487921684e2925b4cf72d6c423718cf4950f3fe"},{"url":"https://github.com/DIRACGrid/DIRAC/commit/f9ddab755b9a69acb85e14d2db851d8ac0c9648c"},{"url":"https://github.com/DIRACGrid/DIRAC"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/dirac/PYSEC-2024-125.yaml"}],"tags":["osv","pip"],"epss":0.00534,"epssPercentile":0.4384,"ingestedAt":"2026-09-12T03:13:01.659Z","slug":"CVE-2024-24825","body":"## Overview\n\n### Impact\n\nAny user could get a token that has been requested by another user/agent\n\n### Patches\nThe vulnerability is fixed in version 8.0.37.\n\n### Workarounds\n\nNone\n\n### References\n\n\n## Affected packages\n\n- `dirac >= 8.0.0, < 8.0.37`\n- `dirac < 8.0.37`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `dirac 8.0.37`\n- `dirac 8.0.37`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}