cbcvebase.
CVE-2018-12021
published 2018-07-05

CVE-2018-12021: Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a…

PriorityP337medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.60%
73.2th percentile
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.

Affected

3 ranges
VendorProductVersion rangeFixed in
debiansingularity-container< singularity-container 2.5.2-1 (sid)singularity-container 2.5.2-1 (sid)
github.comhpcng_singularity>= 2.3.0 < 2.5.22.5.2
sylabssingularity2.3.0 – 2.5.1

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.