First published: Wed Dec 18 2019(Updated: )
Insecure permissions (777) are set on `$HOME/.singularity` when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/sylabs/singularity | >=3.3.0<=3.5.1 | 3.5.2 |
Sylabs Singularity | >=3.3.0<=3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19724 refers to a vulnerability in Singularity, version 3.3.0 to 3.5.1, where insecure permissions (777) are set on $HOME/.singularity, leading to potential information leaks and malicious redirection of operations against Sylabs cloud services.
CVE-2019-19724 has a severity rating of high (7 out of 10).
CVE-2019-19724 affects Singularity versions 3.3.0 to 3.5.1 by setting insecure permissions (777) on $HOME/.singularity, which could lead to information leaks and malicious redirection of operations against Sylabs cloud services.
To fix CVE-2019-19724, update Singularity to version 3.5.2 or later.
More information about CVE-2019-19724 can be found at the following sources: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-19724), [GitHub](https://github.com/sylabs/singularity/releases/tag/v3.5.2), [OpenSUSE](http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html).