---
id: CVE-2024-24825
aliases:
  - GHSA-59qj-jcjv-662j
  - PYSEC-2024-125
title: DIRAC's TokenManager does not check permissions on cached tokens
summary: DIRAC's TokenManager does not check permissions on cached tokens
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
vendor: dirac
product: dirac
ecosystem: pip
affected:
  - 'dirac >= 8.0.0, < 8.0.37'
  - dirac < 8.0.37
patched:
  - dirac 8.0.37
  - dirac 8.0.37
published: '2024-02-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:09.929133236Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-59qj-jcjv-662j'
references:
  - url: 'https://github.com/DIRACGrid/DIRAC/security/advisories/GHSA-59qj-jcjv-662j'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-24825'
  - url: >-
      https://github.com/DIRACGrid/DIRAC/commit/9487921684e2925b4cf72d6c423718cf4950f3fe
  - url: >-
      https://github.com/DIRACGrid/DIRAC/commit/f9ddab755b9a69acb85e14d2db851d8ac0c9648c
  - url: 'https://github.com/DIRACGrid/DIRAC'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/dirac/PYSEC-2024-125.yaml
tags:
  - osv
  - pip
epss: 0.00534
epssPercentile: 0.42615
ingestedAt: '2026-09-12T03:13:01.659Z'
---

## Overview

### Impact

Any user could get a token that has been requested by another user/agent

### Patches
The vulnerability is fixed in version 8.0.37.

### Workarounds

None

### References


## Affected packages

- `dirac >= 8.0.0, < 8.0.37`
- `dirac < 8.0.37`

## Remediation

Upgrade to a patched release:

- `dirac 8.0.37`
- `dirac 8.0.37`
