HIGH
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value
Published Jul 14, 2020
7.5
HIGHCVSS 3.1
EPSS 0.52%
Description
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
Affected products
No data.
- ≥ 3.0.0 · ≤ 3.5.0
No data.
No Red Hat product state for this CVE.
github.com/sylabs/singularity
Go
Introduced 3.0.0 Fixed 3.6.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/sylabs/singularity | 3.0.0 | 3.6.0 |
Remediation
No remediation recorded yet.
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.html vendor-advisoryx_refsource_SUSEBroken Link
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2562 Advisory
- https://github.com/advisories/GHSA-pmfr-63c2-jr5c Advisory
- https://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5c x_refsource_MISCThird Party Advisory
- https://medium.com/sylabs x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-13845
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.html | vendor-advisoryx_refsource_SUSEBroken Link | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2562 | Advisory | |
| https://github.com/advisories/GHSA-pmfr-63c2-jr5c | Advisory | |
| https://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5c | x_refsource_MISCThird Party Advisory | |
| https://medium.com/sylabs | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-13845 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 14, 2020
Updated Aug 4, 2024
Reserved Jun 4, 2020
Link CVE-2020-13845
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-2562 GHSA-PMFR-63C2-JR5C Assigner mitre
Published Jul 14, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2021-2562