CVE-2018-12021: Infoleak
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-12021?
CVE-2018-12021 is a vulnerability in Singularity 2.3.0 through 2.5.1 that allows a malicious user to access sensitive information by exploiting certain Singularity features.
How does CVE-2018-12021 affect Singularity?
CVE-2018-12021 affects Singularity 2.3.0 through 2.5.1 by causing an incorrect access control issue on systems supporting overlay file system.
What is the severity of CVE-2018-12021?
The severity of CVE-2018-12021 is medium, with a CVSS score of 6.5.
Which version of Singularity is affected by CVE-2018-12021?
Singularity versions 2.3.0 through 2.5.1 are affected by CVE-2018-12021.
How can I fix CVE-2018-12021?
To fix CVE-2018-12021, update Singularity to version 2.5.2 or higher.