CVE-2019-19724: High severity singularity vulnerability
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
Other sources
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19724?
CVE-2019-19724 refers to a vulnerability in Singularity, version 3.3.0 to 3.5.1, where insecure permissions (777) are set on $HOME/.singularity, leading to potential information leaks and malicious redirection of operations against Sylabs cloud services.
What is the severity of CVE-2019-19724?
CVE-2019-19724 has a severity rating of high (7 out of 10).
How does CVE-2019-19724 affect Singularity?
CVE-2019-19724 affects Singularity versions 3.3.0 to 3.5.1 by setting insecure permissions (777) on $HOME/.singularity, which could lead to information leaks and malicious redirection of operations against Sylabs cloud services.
How can I fix CVE-2019-19724?
To fix CVE-2019-19724, update Singularity to version 3.5.2 or later.
Where can I find more information about CVE-2019-19724?
More information about CVE-2019-19724 can be found at the following sources: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-19724), [GitHub](https://github.com/sylabs/singularity/releases/tag/v3.5.2), [OpenSUSE](http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html).