Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Singularity Container Services Library HIGH 7.6
CVE-2022-23538

github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-cl…

Patch available
Fix from $1,950 2023-01-17
Singularity Image Format CRITICAL 9.8
CVE-2022-39237

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` pa…

Fix: 2.8.1+
Fix from $2,300 2022-10-06
Singularity CRITICAL 9.8
CVE-2021-33027

Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.

Fix: 1.2.6 / 1.3.4+
Fix from $2,300 2021-07-19
Singularity CRITICAL 9.8
CVE-2021-33622

Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.

Fix: 3.5-8 / 3.7.0+
Fix from $2,300 2021-06-15
Singularity MEDIUM 6.3
CVE-2021-32635

Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`…

Mitigation only
Fix from $1,600 2021-05-28
Singularity Image Format HIGH 7.5
CVE-2021-29499

SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable …

Fix: 1.2.3+
Fix from $1,950 2021-05-07
Singularity CRITICAL 9.3
CVE-2020-15229

Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and …

Fix: after 3.6.3
Fix from $2,300 2020-10-14
Singularity HIGH 8.8
CVE-2020-25040

Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a differ…

Fix: after 3.6.2
Fix from $1,950 2020-09-16
Singularity HIGH 8.1
CVE-2020-25039

Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.

Fix: after 3.6.2
Fix from $1,950 2020-09-16
Singularity HIGH 7.5
CVE-2020-13845

Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforc…

Fix: after 3.5.0
Fix from $1,950 2020-07-14
Singularity HIGH 7.5
CVE-2020-13846

Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.

Fix: after 3.5.3
Fix from $1,950 2020-07-14
Singularity HIGH 7.5
CVE-2020-13847

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the glo…

Fix: after 3.5.0
Fix from $1,950 2020-07-14
Singularity HIGH 7.5
CVE-2019-19724

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to a…

Fix: after 3.5.1
Fix from $1,950 2019-12-18
Singularity HIGH 7.8
CVE-2018-19295

Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.

Fix: after 2.6.0
Fix from $1,950 2018-12-17
Singularity MEDIUM 6.5
CVE-2018-12021

Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, …

Fix: after 2.5.1
Fix from $1,600 2018-07-05