CVE-2023-30549
- EPSS 0.03%
- Veröffentlicht 25.04.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:00:24
Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE h...
CVE-2021-33027
- EPSS 0.61%
- Veröffentlicht 19.07.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:09
Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
CVE-2021-33622
- EPSS 0.55%
- Veröffentlicht 15.06.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 06:09:12
Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.
CVE-2021-32635
- EPSS 0.63%
- Veröffentlicht 28.05.2021 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:25
Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve ...
CVE-2021-29136
- EPSS 0.15%
- Veröffentlicht 06.04.2021 16:15:16
- Zuletzt bearbeitet 21.11.2024 06:00:45
Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.
CVE-2020-15229
- EPSS 0.88%
- Veröffentlicht 14.10.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:05:08
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on th...
CVE-2020-25039
- EPSS 0.82%
- Veröffentlicht 16.09.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:16:51
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
CVE-2020-25040
- EPSS 0.74%
- Veröffentlicht 16.09.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:16:54
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
CVE-2020-13845
- EPSS 0.08%
- Veröffentlicht 14.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:59
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the...
CVE-2020-13846
- EPSS 0.37%
- Veröffentlicht 14.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:59
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.