CVE-2024-29905High· 8.1▾ TwilightDIRAC: Unauthorized users can read proxy contents during generation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
During the proxy generation process (e.g., when using dirac-proxy-init) it is possible for unauthorized users on the same machine to gain read access to the proxy. This allows the user to then perform any action that is possible with the original proxy.
This vulnerability only exists for a short period of time (sub-millsecond) during the generation process.
Has the problem been patched? What versions should users upgrade to?
Setting the X509_USER_PROXY environment variable to a path that is inside a directory that is only readable to the current user avoids the potential risk. After the file has been written it can be safely copied to the standard location (/tmp/x509up_uNNNN).
dirac < 8.0.41Upgrade to a patched release:
dirac 8.0.41Connected by shared product, vendor, weakness, or advisory.
CVE-2024-24825Critical· 9.1DIRAC's TokenManager does not check permissions on cached tokens
CVE-2026-61667Critical· 9.9DIRAC is an interware, meaning a software framework for distributed computing
CVE-2026-61668High· 8.1DIRAC is an interware, meaning a software framework for distributed computing
GHSA-7xw9-549r-8jrcHigh· 8.5DIRAC: SQL injection and lack of access control in PilotManager service
CVE-2026-45579Critical· 9.9DIRAC is an interware, meaning a software framework for distributed computing