📦

singularity

Vendor: sylabs

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 18 Total Indexed
Avg. EPSS 1.25% Exploit Prob.
Latest CVE CVE-2023-30549 Apr 25

Security Vulnerability Index

Page 2 / 2
7.5 CVSS

Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.

EPSS: 0.52%
7.5 CVSS

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.

EPSS: 1.23%
8.8 CVSS

An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.

EPSS: 2.13%
7.8 CVSS

Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.

EPSS: 0.47%
6.5 CVSS

Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.

EPSS: 1.60%