Sylabs

Singularity

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 15.09.2026 15:07:49
  • Zuletzt bearbeitet 25.09.2026 14:23:59

SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a container in a sib...

  • EPSS 0.16%
  • Veröffentlicht 02.12.2025 17:25:55
  • Zuletzt bearbeitet 15.04.2026 00:35:42

SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.3.5 and SingularityPRO 4.1.11 and 4.3.5, if a user relies on LSM restrictions to prevent malicious operations then, under certain circumstances, an attacke...

  • EPSS 0.37%
  • Veröffentlicht 25.04.2023 21:15:10
  • Zuletzt bearbeitet 21.11.2024 08:00:24

Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE h...

  • EPSS 1.33%
  • Veröffentlicht 19.07.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 06:08:09

Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.

  • EPSS 1.26%
  • Veröffentlicht 15.06.2021 20:15:14
  • Zuletzt bearbeitet 21.11.2024 06:09:12

Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.

  • EPSS 1.42%
  • Veröffentlicht 28.05.2021 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:25

Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve ...

  • EPSS 0.34%
  • Veröffentlicht 06.04.2021 16:15:16
  • Zuletzt bearbeitet 21.11.2024 06:00:45

Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.

  • EPSS 2.05%
  • Veröffentlicht 14.10.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:05:08

Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on th...

  • EPSS 2.04%
  • Veröffentlicht 16.09.2020 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:16:54

Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.

  • EPSS 2.01%
  • Veröffentlicht 16.09.2020 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:16:51

Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.