Impact
The vulnerability resides in an eval call that processes an untrusted groupingAttribute passed by an authenticated caller to the export_getRequestCountersWeb function in the RequestManager. The unrecognized value is resolved against the Request object and evaluated as raw Python code, enabling a crafted expression to invoke operating‑system functions and execute commands as the user running the DIRAC services. An attacker can therefore read or modify the dirac.cfg file, obtain database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and alter local log evidence. The flaw is a classic use of eval on untrusted data (CWE‑95).
Affected Systems
DIRACGrid’s DIRAC interware, versions older than 8.0.79, 9.0.22, and 9.1.10. All releases prior to those patch releases contain the vulnerable code. Updated releases 8.0.79 or newer, 9.0.22 or newer, and 9.1.10 or newer contain the fix that removes the eval path.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score is < 1%, indicating a low probability of exploitation today, yet the absence of a public exploit does not reduce the risk to systems that remain on vulnerable versions. The attack requires an authenticated user to invoke the RequestManager endpoint; once authenticated, the attacker can inject any Python expression that the service will evaluate. If successfully exploited, the attacker can read sensitive files, exfiltrate credentials, and alter local log evidence, effectively taking over the DIRAC deployment.
OpenCVE Enrichment
Github GHSA