Sylabs Sif vulnerabilities
2 known vulnerabilities affecting sylabs/sif.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2022-39237CRITICALCVSS 9.8fixed in 2.8.12022-10-06
CVE-2022-39237 [CRITICAL] CWE-347 CVE-2022-39237: syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is available in version >= v2.8.1 of the module. Users are encouraged to up
nvd
CVE-2021-29499HIGHCVSS 7.5≤ 1.2.22021-05-07
CVE-2021-29499 [HIGH] CWE-330 CVE-2021-29499: SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` co
SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged to
nvd