Vulnerability CVE-2020-13845


Published: 2020-07-14

Description:
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.

Type:

CWE-347

(Improper Verification of Cryptographic Signature)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Sylabs -> Singularity 

 References:
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.html
https://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5c
https://medium.com/sylabs

Copyright 2024, cxsecurity.com

 

Back to Top