Skip to main content

Vendor/product archive

sylabs / singularity CVEs

Beta · best-effort

15 CVEs tagged to sylabs / singularity2 Critical, 10 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2021-32635

Published May 28, 2021

Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifyin…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29136

Published Apr 6, 2021

Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25040

Published Sep 16, 2020

Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-202…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13847

Published Jul 14, 2020

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object desc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13846

Published Jul 14, 2020

Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13845

Published Jul 14, 2020

Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19724

Published Dec 18, 2019

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malici…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-19295

Published Dec 17, 2018

Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12021

Published Jul 5, 2018

Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1