DIRACGrid records
2 published records for vendor diracgrid.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-668 Exposure of Resource to Wrong Sphere1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2024-24825No exploit | TokenManager not checking permissions on cached tokens in DIRACdiracgrid · dirac · CWE-200 | High7.5 | — | 0.5% | Feb 8, 2024 |
22Monitor | CVE-2024-29905No exploit | DIRAC: Unauthorized users can read proxy contents during generationdiracgrid · dirac · CWE-668 | Medium5.5 | — | 0.3% | Apr 9, 2024 |
- CVE-2024-2482530Monitor
TokenManager not checking permissions on cached tokens in DIRAC
HighCVSS 7.5No exploitEPSS 1%diracgrid · diracFeb 8, 2024
- CVE-2024-2990522Monitor
DIRAC: Unauthorized users can read proxy contents during generation
MediumCVSS 5.5No exploitEPSS 0%diracgrid · diracApr 9, 2024