Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2020-25040

Disclosure Date: September 16, 2020 (last updated February 22, 2025)
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
Attacker Value
Unknown

CVE-2020-13847

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.
Attacker Value
Unknown

CVE-2020-13845

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
Attacker Value
Unknown

CVE-2020-13846

Disclosure Date: July 14, 2020 (last updated February 21, 2025)
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
Attacker Value
Unknown

CVE-2019-19724

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
Attacker Value
Unknown

CVE-2019-11328

Disclosure Date: May 14, 2019 (last updated November 08, 2023)
An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.
Attacker Value
Unknown

CVE-2018-19295

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
0
Attacker Value
Unknown

CVE-2018-12021

Disclosure Date: July 05, 2018 (last updated November 27, 2024)
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
0