First published: Tue Jul 14 2020(Updated: )
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sylabs Singularity | >=3.0.0<=3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13847 is a vulnerability in Sylabs Singularity versions 3.0 through 3.5 that lacks support for an Integrity Check.
CVE-2020-13847 affects Sylabs Singularity versions 3.0 through 3.5.
CVE-2020-13847 has a severity rating of high (7.5).
CVE-2020-13847 is associated with the CWE-354: Improper Check for Integrity of Code Vulnerability.
To fix CVE-2020-13847, it is recommended to update Sylabs Singularity to a version that includes support for an Integrity Check.