Résumé
DIRAC: Pilot code downloaded over unverified HTTPS connection
Détails de l’avis
Summary
The second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel.
Details
The pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296
This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials).
The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly.
Impact
This would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact.
Patched versions:
https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/
Références
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-55215
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
- MEDIUMCVE-2026-63336
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
- MEDIUMCVE-2026-69248
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
- CRITICALCVE-2026-46428
lettre has TLS hostname verification disabled when using Boring TLS backend
- HIGHCVE-2026-56820
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
- HIGHCVE-2026-54481
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override