First published: Wed Sep 16 2020(Updated: )
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sylabs Singularity | <=3.6.2 | |
openSUSE | =15.1 | |
openSUSE | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-25040.
The severity of CVE-2020-25040 is high with a CVSS score of 8.8.
The affected software for CVE-2020-25040 is Sylabs Singularity version up to 3.6.2 and openSUSE Leap versions 15.1 and 15.2.
CVE-2020-25040 refers to Sylabs Singularity through 3.6.2 having insecure permissions on temporary directories used in explicit and implicit container build operations.
Yes, you can find more information about CVE-2020-25040 at the following references: [1](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00070.html), [2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00088.html), [3](https://github.com/hpcng/singularity/security/advisories/GHSA-jv9c-w74q-6762).