First published: Thu Jul 05 2018(Updated: )
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/hpcng/singularity | >=2.3.0<=2.5.1 | 2.5.2 |
Sylabs Singularity | >=2.3.0<=2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12021 is a vulnerability in Singularity 2.3.0 through 2.5.1 that allows a malicious user to access sensitive information by exploiting certain Singularity features.
CVE-2018-12021 affects Singularity 2.3.0 through 2.5.1 by causing an incorrect access control issue on systems supporting overlay file system.
The severity of CVE-2018-12021 is medium, with a CVSS score of 6.5.
Singularity versions 2.3.0 through 2.5.1 are affected by CVE-2018-12021.
To fix CVE-2018-12021, update Singularity to version 2.5.2 or higher.