CVE-2021-32635
published 2021-05-28CVE-2021-32635: Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands…
PriorityP335medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
1.42%
69.7th percentile
Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint. An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container. Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint. The vulnerability is patched in Singularity version 3.7.4. Two possible workarounds exist: Users can only interact with the default remote endpoint, or an installation can have an execution control list configured to restrict execution to containers signed with specific secure keys.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | singularity-container | — | — |
| github.com | sylabs_singularity | >= 3.7.2 < 3.7.4 | 3.7.4 |
| sylabs | singularity | — | — |
| sylabs | singularity | — | — |
| sylabs | singularity | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.3MEDIUM
vendor_debian6.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
ghsa·2021-06-01
CVE-2021-32635 [MEDIUM] CWE-20 Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
### Impact
Due to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint.
An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container.
Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint.
### Patches
All users should up
OSV
Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
osv·2021-06-01
CVE-2021-32635 [MEDIUM] Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
### Impact
Due to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint.
An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container.
Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint.
### Patches
All users should up
OSV
CVE-2021-32635: Singularity is an open source container platform
osv·2021-05-28·CVSS 6.3
CVE-2021-32635 [MEDIUM] CVE-2021-32635: Singularity is an open source container platform
Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint. An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container. Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint. The vulnerability is patched in Singularity version 3.7.4.
Debian
CVE-2021-32635: singularity-container - Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dd...
vendor_debian·2021·CVSS 6.3
CVE-2021-32635 [MEDIUM] CVE-2021-32635: singularity-container - Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dd...
Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint. An attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container. Only action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint. The vulnerability is patched in Singularity version 3.7.4.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/sylabs/singularity/releases/tag/v3.7.4https://github.com/sylabs/singularity/security/advisories/GHSA-5mv9-q7fq-9394https://security.gentoo.org/glsa/202107-50https://github.com/sylabs/singularity/releases/tag/v3.7.4https://github.com/sylabs/singularity/security/advisories/GHSA-5mv9-q7fq-9394https://security.gentoo.org/glsa/202107-50
2021-05-28
Published