CVE-2020-15229
published 2020-10-14CVE-2020-15229: Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack…
PriorityP351critical9.3CVSS 3.1
AVNACLPRNUIRSCCHIHAN
EPSS
2.05%
79.0th percentile
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the extraction with a crafted squashfs filesystem. The extraction occurs automatically for unprivileged (either installation or with `allow setuid = no`) run of Singularity when a user attempt to run an image which is a local SIF image or a single file containing a squashfs filesystem and is coming from remote sources `library://` or `shub://`. Image build is also impacted in a more serious way as it can be used by a root user, allowing an attacker to overwrite/create files leading to a system compromise, so far bootstrap methods `library`, `shub` and `localimage` are triggering the squashfs extraction. This issue is addressed in Singularity 3.6.4. All users are advised to upgrade to 3.6.4 especially if they use Singularity mainly for building image as root user. There is no solid workaround except to temporary avoid to use unprivileged mode with single file images in favor of sandbox images instead. Regarding image build, temporary avoid to build from `library` and `shub` sources and as much as possible use `--fakeroot` or a VM for that.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | singularity-container | < singularity-container 3.9.5+ds1-2 (sid) | singularity-container 3.9.5+ds1-2 (sid) |
| github.com | sylabs_singularity | >= 3.1.1 < 3.6.4 | 3.6.4 |
| hpcng | singularity | < 3.6.4 | 3.6.4 |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| sylabs | singularity | 3.1.1 – 3.6.3 | — |
CVSS provenance
nvdv3.19.3CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_debian8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2020-15229: singularity-container - Singularity (an open source container platform) from version 3.1.1 through 3.6.3...
vendor_debian·2020·CVSS 8.2
CVE-2020-15229 [HIGH] CVE-2020-15229: singularity-container - Singularity (an open source container platform) from version 3.1.1 through 3.6.3...
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the extraction with a crafted squashfs filesystem. The extraction occurs automatically for unprivileged (either installation or with `allow setuid = no`) run of Singularity when a user attempt to run an image which is a local SIF image or a single file containing a squashfs filesystem and is coming from remote sources `library://` or `shub://`. Image build is also impacted in a more serious way as it can be used by a root user, allowing an attacker to overwrite/create files leading to a system compromise, so far bootstr
GHSA
Path traversal and files overwrite with unsquashfs in singularity
ghsa·2021-05-24
CVE-2020-15229 [HIGH] CWE-22 Path traversal and files overwrite with unsquashfs in singularity
Path traversal and files overwrite with unsquashfs in singularity
### Impact
Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs` (a distribution provided utility used by Singularity), it is possible to overwrite/create any files on the host filesystem during the extraction of a crafted squashfs filesystem.
Squashfs extraction occurs automatically for unprivileged execution of Singularity (either `--without-suid` installation or with `allow setuid = no`) when a user attempts to run an image which:
- is a local SIF image or a single file containing a squashfs filesystem
- is pulled from remote sources `library://` or `shub://`
Image build is also impacted in a more serious way as it is often performed by the root user, allowing an attacker to
OSV
Path traversal and files overwrite with unsquashfs in singularity
osv·2021-05-24
CVE-2020-15229 [HIGH] Path traversal and files overwrite with unsquashfs in singularity
Path traversal and files overwrite with unsquashfs in singularity
### Impact
Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs` (a distribution provided utility used by Singularity), it is possible to overwrite/create any files on the host filesystem during the extraction of a crafted squashfs filesystem.
Squashfs extraction occurs automatically for unprivileged execution of Singularity (either `--without-suid` installation or with `allow setuid = no`) when a user attempts to run an image which:
- is a local SIF image or a single file containing a squashfs filesystem
- is pulled from remote sources `library://` or `shub://`
Image build is also impacted in a more serious way as it is often performed by the root user, allowing an attacker to
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs [epel-all]
bugzilla·2020-10-15·CVSS 8.2
CVE-2020-15229 [HIGH] CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs [epel-all]
CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs
bugzilla·2020-10-15·CVSS 8.2
CVE-2020-15229 [HIGH] CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs
CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to overwrite/create any files on the host filesystem during the extraction with a crafted squashfs filesystem. The extraction occurs automatically for unprivileged (either installation or with `allow setuid = no`) run of Singularity when a user attempt to run an image which is a local SIF image or a single file containing a squashfs filesystem and is coming from remote sources `library://` or `shub://`. Image build is also impacted in a more serious way as it can be used by a root user, allowing an a
Bugzilla
CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs [fedora-all]
bugzilla·2020-10-15·CVSS 8.2
CVE-2020-15229 [HIGH] CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs [fedora-all]
CVE-2020-15229 singularity: path traversal and files overwrite with unsquashfs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00070.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00071.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00009.htmlhttps://github.com/hpcng/singularity/blob/v3.6.4/CHANGELOG.md#security-related-fixeshttps://github.com/hpcng/singularity/commit/eba3dea260b117198fdb6faf41f2482ab2f8d53ehttps://github.com/hpcng/singularity/pull/5611https://github.com/hpcng/singularity/security/advisories/GHSA-7gcp-w6ww-2xv9http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00070.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00071.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-11/msg00009.htmlhttps://github.com/hpcng/singularity/blob/v3.6.4/CHANGELOG.md#security-related-fixeshttps://github.com/hpcng/singularity/commit/eba3dea260b117198fdb6faf41f2482ab2f8d53ehttps://github.com/hpcng/singularity/pull/5611https://github.com/hpcng/singularity/security/advisories/GHSA-7gcp-w6ww-2xv9
2020-10-14
Published