CVE-2018-12021
published 2018-07-05CVE-2018-12021: Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a…
PriorityP337medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.60%
73.2th percentile
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | singularity-container | < singularity-container 2.5.2-1 (sid) | singularity-container 2.5.2-1 (sid) |
| github.com | hpcng_singularity | >= 2.3.0 < 2.5.2 | 2.5.2 |
| sylabs | singularity | 2.3.0 – 2.5.1 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Singularity Incorrect Access Control
ghsa·2022-05-14
CVE-2018-12021 [MEDIUM] CWE-200 Singularity Incorrect Access Control
Singularity Incorrect Access Control
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
OSV
Singularity Incorrect Access Control
osv·2022-05-14
CVE-2018-12021 [MEDIUM] Singularity Incorrect Access Control
Singularity Incorrect Access Control
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
OSV
singularity-container vulnerabilities
osv·2021-03-15·CVSS 6.5
CVE-2018-19295 [MEDIUM] singularity-container vulnerabilities
singularity-container vulnerabilities
It was discovered that Singularity incorrectly handled certain inputs. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2018-19295)
It was discovered that Singularity incorrectly handled access control. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2018-12021)
OSV
CVE-2018-12021: Singularity 2
osv·2018-07-05·CVSS 6.5
CVE-2018-12021 [MEDIUM] CVE-2018-12021: Singularity 2
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
Ubuntu
Singularity vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 6.5
CVE-2018-12021 [MEDIUM] Singularity vulnerabilities
Title: Singularity vulnerabilities
Summary: Several security issues were fixed in Singularity.
It was discovered that Singularity incorrectly handled certain inputs. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2018-19295)
It was discovered that Singularity incorrectly handled access control. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2018-12021)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-12021: singularity-container - Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on sy...
vendor_debian·2018·CVSS 6.5
CVE-2018-12021 [MEDIUM] CVE-2018-12021: singularity-container - Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on sy...
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features.
Scope: local
sid: resolved (fixed in 2.5.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-07-05
Published