Skip to main content

Vendor archive

sylabs CVEs

Beta · best-effort

18 CVEs tagged to vendor sylabs2 Critical, 11 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2022-39237

Published Oct 6, 2022

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32635

Published May 28, 2021

Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifyin…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29499

Published May 7, 2021

SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29136

Published Apr 6, 2021

Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25040

Published Sep 16, 2020

Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-202…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13847

Published Jul 14, 2020

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object desc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13846

Published Jul 14, 2020

Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13845

Published Jul 14, 2020

Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19724

Published Dec 18, 2019

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malici…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19295

Published Dec 17, 2018

Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12021

Published Jul 5, 2018

Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1