CVE-2018-19295
published 2018-12-17CVE-2018-19295: Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
PriorityP434high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.47%
37.4th percentile
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | singularity-container | < singularity-container 2.6.1-1 (sid) | singularity-container 2.6.1-1 (sid) |
| github.com | sylabs_singularity | >= 2.4.0 < 2.6.1 | 2.6.1 |
| sylabs | singularity | 2.4 – 2.6.0 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Singularity vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 6.5
CVE-2018-12021 [MEDIUM] Singularity vulnerabilities
Title: Singularity vulnerabilities
Summary: Several security issues were fixed in Singularity.
It was discovered that Singularity incorrectly handled certain inputs. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2018-19295)
It was discovered that Singularity incorrectly handled access control. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2018-12021)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-19295: singularity-container - Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Valid...
vendor_debian·2018·CVSS 7.8
CVE-2018-19295 [HIGH] CVE-2018-19295: singularity-container - Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Valid...
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
Scope: local
sid: resolved (fixed in 2.6.1-1)
GHSA
Sylabs Singularity Improper Input Validation
ghsa·2022-05-14
CVE-2018-19295 [HIGH] CWE-20 Sylabs Singularity Improper Input Validation
Sylabs Singularity Improper Input Validation
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
OSV
Sylabs Singularity Improper Input Validation
osv·2022-05-14
CVE-2018-19295 [HIGH] Sylabs Singularity Improper Input Validation
Sylabs Singularity Improper Input Validation
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
OSV
singularity-container vulnerabilities
osv·2021-03-15·CVSS 6.5
CVE-2018-19295 [MEDIUM] singularity-container vulnerabilities
singularity-container vulnerabilities
It was discovered that Singularity incorrectly handled certain inputs. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2018-19295)
It was discovered that Singularity incorrectly handled access control. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2018-12021)
OSV
CVE-2018-19295: Sylabs Singularity 2
osv·2018-12-17·CVSS 7.8
CVE-2018-19295 [HIGH] CVE-2018-19295: Sylabs Singularity 2
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-12-17
Published