VulnerabilityModified
CVE-2020-13845
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value.
HIGH 7.5EPSS 0.52%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.52% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347, CWE-354
- Affected
- sylabs/singularity
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.htmlBroken Link
- https://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5cThird Party Advisory
- https://medium.com/sylabsThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.htmlBroken Link
- https://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5cThird Party Advisory
- https://medium.com/sylabsThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.