Описание
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
Ссылки
- Broken Link
- Broken Link
- Broken Link
- Third Party Advisory
- Third Party Advisory
- Broken Link
- Broken Link
- Broken Link
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integ ...
Execution Control List (ECL) Is Insecure in Singularity
EPSS
7.5 High
CVSS3
5 Medium
CVSS2