Impact
Prior to versions 8.0.79, 9.0.22, and 9.1.10, the DataManagementSystem/Service/FileCatalogHandler.py checkDataset function forwards an authenticated caller‑controlled datasets value to DatasetManager.py __checkDataset, where the datasetName is interpolated into an FC_MetaDatasets SQL query without parameterization (CWE‑89). The injected query can manipulate the returned MetaQuery value, which is then passed to Python eval (CWE‑95) and permits command execution as the account running the DIRAC services. Successful exploitation can expose dirac.cfg, database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and allow alteration of local log evidence, effectively granting an attacker full control over the system.
Affected Systems
DIRACGrid:DIRAC interware, specifically the DataManagement System’s FileCatalogHandler component, is affected. The vulnerability resides in all releases before 8.0.79, 9.0.22, and 9.1.10.
Risk and Exploitability
The CVSS score of 9.9 marks the flaw as critical. Exploitation requires an authenticated session to the service, so attackers need legitimate access or escalating privileges. The EPSS score of <1% indicates a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The combination of unsanitized SQL with eval renders it highly exploitable within a compromised or authorized deployment.
OpenCVE Enrichment
Github GHSA