5
CVSSv2

CVE-2020-13845

Published: 14/07/2020 Updated: 20/01/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Sylabs Singularity 3.0 up to and including 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sylabs singularity

Vendor Advisories

Debian Bug report logs - #965040 singularity-container: CVE-2020-13845 CVE-2020-13846 CVE-2020-13847 Package: src:singularity-container; Maintainer for src:singularity-container is Debian HPC Team <debian-hpc@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 14 Jul 2020 19:42:01 UTC ...