HIGH7.5
GHSA-mj73-5x75-9phh
Singularity insecure permissions
Quick fix
GHSA-mj73-5x75-9phh — github.com/sylabs/singularity: upgrade to the fixed version with the command below.
go get github.com/sylabs/singularity@v3.5.2Details
Insecure permissions (777) are set on `$HOME/.singularity` when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/sylabs/singularity
Introduced in:
3.3.0Fixed in: 3.5.2Fix
go get github.com/sylabs/singularity@v3.5.2References
- https://nvd.nist.gov/vuln/detail/CVE-2019-19724[ADVISORY]
- https://github.com/sylabs/singularity/commit/2cda4981812c29f0fb11d3ea6aaf6139f665a631[WEB]
- https://github.com/sylabs/singularity[PACKAGE]
- https://github.com/sylabs/singularity/releases/tag/v3.5.2[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html[WEB]