Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://medium.com/sylabs | product |
https://github.com/hpcng/singularity/security/advisories/GHSA-w6v2-qchm-grj7 | third party advisory mitigation |
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00070.html | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00088.html | third party advisory vendor advisory |