Sylabs
Sylabs Singularity: vulnerabilidades y CVE
Sylabs Singularity tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-30549 | Alta (7.8) | 0.37% | — | 25 abr 2023 | Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older… |
| CVE-2021-33027 | Crítica (9.8) | 1.3% | — | 19 jul 2021 | Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce. |
| CVE-2021-33622 | Crítica (9.8) | 1.3% | — | 15 jun 2021 | Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value. |
| CVE-2021-32635 | Media (6.3) | 1.4% | — | 28 may 2021 | Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI… |
| CVE-2021-29136 | Media (5.5) | 0.34% | — | 6 abr 2021 | Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used. |
| CVE-2020-15229 | Crítica (9.3) | 2.0% | — | 14 oct 2020 | Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to… |
| CVE-2020-25040 | Alta (8.8) | 2.0% | — | 16 sept 2020 | Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039. |
| CVE-2020-25039 | Alta (8.1) | 2.0% | — | 16 sept 2020 | Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution. |
| CVE-2020-13847 | Alta (7.5) | 0.63% | — | 14 jul 2020 | Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file. |
| CVE-2020-13846 | Alta (7.5) | 1.3% | — | 14 jul 2020 | Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code. |
| CVE-2020-13845 | Alta (7.5) | 0.52% | — | 14 jul 2020 | Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the… |
| CVE-2019-19724 | Alta (7.5) | 1.2% | — | 18 dic 2019 | Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed… |
| CVE-2019-11328 | Alta (8.8) | 2.1% | — | 14 may 2019 | An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit… |
| CVE-2018-19295 | Alta (7.8) | 0.47% | — | 17 dic 2018 | Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks. |
| CVE-2018-12021 | Media (6.5) | 1.6% | — | 5 jul 2018 | Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few… |