CVE-2020-13847

high

Description

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.

References

https://medium.com/sylabs

https://github.com/hpcng/singularity/security/advisories/GHSA-m7j2-9565-4h9v

Details

Source: Mitre, NVD

Published: 2020-07-14

Updated: 2023-01-20

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High