Impact
DIRAC is an interware framework for distributed computing that uses a pilot wrapper to execute third-party code. Before the release of versions 8.0.79, 9.0.22, and 9.1.10 a second-stage pilot.tar archive and its reference checksum were transferred over an HTTPS connection created by ssl._create_unverified_context, which performs no TLS certificate validation. An attacker who can redirect or intercept the grid site’s traffic through DNS or routing manipulation can substitute both the executable pilot code and its checksum, resulting in arbitrary code execution within the pilot environment with the pilot proxy credentials. The issue is a TLS certificate validation flaw (CWE-295) and was fixed by validating the server certificate against the system trust store or the grid certificate directory.
Affected Systems
Affected releases are DIRACGrid DIRAC versions prior to 8.0.79, 9.0.22, and 9.1.10. Any deployment of these versions that uses the default pilot wrapper is susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, classifying it as high severity. The EPSS score is under 1%, indicating a low yet non-zero probability of exploitation, and it is not currently listed in CISA’s KEV catalog. Exploitation requires an attacker with the ability to alter DNS or routing to redirect pilot download traffic; no local privileges are required. If successful, the attacker gains code execution with the pilot’s proxy credentials, compromising confidentiality, integrity, and availability for the workload.
OpenCVE Enrichment
Github GHSA