Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2020-25040
Disclosure Date: September 16, 2020 (last updated February 22, 2025)
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
0
Attacker Value
Unknown
CVE-2020-13847
Disclosure Date: July 14, 2020 (last updated February 21, 2025)
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.
0
Attacker Value
Unknown
CVE-2020-13845
Disclosure Date: July 14, 2020 (last updated February 21, 2025)
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
0
Attacker Value
Unknown
CVE-2020-13846
Disclosure Date: July 14, 2020 (last updated February 21, 2025)
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
0
Attacker Value
Unknown
CVE-2019-19724
Disclosure Date: December 18, 2019 (last updated November 27, 2024)
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
0
Attacker Value
Unknown
CVE-2019-11328
Disclosure Date: May 14, 2019 (last updated November 08, 2023)
An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.
0
Attacker Value
Unknown
CVE-2018-19295
Disclosure Date: December 17, 2018 (last updated November 27, 2024)
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
0
Attacker Value
Unknown
CVE-2018-12021
Disclosure Date: July 05, 2018 (last updated November 27, 2024)
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
0