Description
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4576 | Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services. |
Github GHSA |
GHSA-mj73-5x75-9phh | Singularity insecure permissions |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:25:12.399Z
Reserved: 2019-12-11T00:00:00.000Z
Link: CVE-2019-19724
No data.
Status : Modified
Published: 2019-12-18T21:15:13.757
Modified: 2026-06-17T02:27:08.630
Link: CVE-2019-19724
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-276
Incorrect Default Permissions
EUVD
Github GHSA