Incorrect default permissions in Singularity - CVE-2019-19724
Published: July 23, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure permissions for files and folders that are set by the application on $HOME/.singularity file when it is newly created by Singularity. A local user with access to the system can view contents of files and directories or modify them.
Affected software
singularity (Alpine package)
Opensuse
How to mitigate CVE-2019-19724
singularity (Alpine package) - update to 3.5.2-r0