CVE-2020-13845
published 2020-07-14CVE-2020-13845: Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.52%
40.5th percentile
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | singularity-container | < singularity-container 3.9.5+ds1-2 (sid) | singularity-container 3.9.5+ds1-2 (sid) |
| github.com | sylabs_singularity | >= 3.0.0 < 3.6.0 | 3.6.0 |
| sylabs | singularity | 3.0.0 – 3.5.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2020-13845: singularity-container - Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check...
vendor_debian·2020·CVSS 7.5
CVE-2020-13845 [HIGH] CVE-2020-13845: singularity-container - Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check...
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
Scope: local
sid: resolved (fixed in 3.9.5+ds1-2)
OSV
Execution Control List (ECL) Is Insecure in Singularity
osv·2021-12-20
CVE-2020-13845 [HIGH] Execution Control List (ECL) Is Insecure in Singularity
Execution Control List (ECL) Is Insecure in Singularity
### Impact
The Singularity Execution Control List (ECL) allows system administrators to set up a policy that defines rules about what signature(s) must be (or must not be) present on a SIF container image for it to be permitted to run.
In Singularity 3.x versions below 3.6.0, the following issues allow the ECL to be bypassed by a malicious user:
* Image integrity is not validated when an ECL policy is enforced.
* The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature. Thus, it is trivial to craft an arbitrary payload which will be permitted to run, even if the attacker does not have access to the private key associated with
GHSA
Execution Control List (ECL) Is Insecure in Singularity
ghsa·2021-12-20
CVE-2020-13845 [HIGH] CWE-347 Execution Control List (ECL) Is Insecure in Singularity
Execution Control List (ECL) Is Insecure in Singularity
### Impact
The Singularity Execution Control List (ECL) allows system administrators to set up a policy that defines rules about what signature(s) must be (or must not be) present on a SIF container image for it to be permitted to run.
In Singularity 3.x versions below 3.6.0, the following issues allow the ECL to be bypassed by a malicious user:
* Image integrity is not validated when an ECL policy is enforced.
* The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature. Thus, it is trivial to craft an arbitrary payload which will be permitted to run, even if the attacker does not have access to the private key associated with
OSV
CVE-2020-13845: Sylabs Singularity 3
osv·2020-07-14·CVSS 7.5
CVE-2020-13845 [HIGH] CVE-2020-13845: Sylabs Singularity 3
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.htmlhttps://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5chttps://medium.com/sylabshttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.htmlhttps://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5chttps://medium.com/sylabs
2020-07-14
Published