CVE-2019-19724

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-19724
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19724.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-19724
Aliases
Related
Published
2019-12-18T21:15:13Z
Modified
2025-05-24T03:15:25.940578Z
Downstream
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.

References

Affected packages

Git / github.com/hpcng/singularity

Affected ranges

Type
GIT
Repo
https://github.com/hpcng/singularity
Events
Type
GIT
Repo
https://github.com/sylabs/singularity
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

1.*

1.0

2.*

2.0
2.1
2.1.1
2.1.2
2.2
2.3
2.3.1
2.3.2
2.4
2.4.1
2.4.2

v3.*

v3.0.0
v3.0.0-alpha.1
v3.0.0-alpha.2
v3.0.0-beta.1
v3.0.1
v3.0.2
v3.0.2-rc1
v3.0.2-rc2
v3.0.3
v3.0.3-rc1
v3.0.3-rc2
v3.1.0
v3.1.0-rc1
v3.1.0-rc2
v3.1.0-rc3
v3.1.0-rc4
v3.1.1
v3.1.1-rc1
v3.2.0
v3.2.0-rc1
v3.2.0-rc2
v3.2.1
v3.2.1-rc1
v3.3.0
v3.3.0-rc.1
v3.3.0-rc.2
v3.3.0-rc.3
v3.3.0-rc.4
v3.4.0
v3.4.0-rc.1
v3.4.0-rc.2
v3.4.1
v3.4.1-rc.1
v3.4.2
v3.4.2-rc.1
v3.5.0
v3.5.0-rc.1
v3.5.0-rc.2
v3.5.1
v3.5.1-rc.1
v3.5.1-rc.2