← Retour aux CVEs
CVE-2020-13845
HIGH7.5
Description
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
Details CVE
Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie7/14/2020
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
sylabs:singularity
Faiblesses (CWE)
CWE-347CWE-354
References
https://medium.com/sylabs(cve@mitre.org)
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.html(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5c(af854a3a-2127-422b-91ae-364da2661108)
https://medium.com/sylabs(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.