CVE-2020-13846

Name
CVE-2020-13846
Description
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://medium.com/sylabs
Third Party Advisory https://github.com/hpcng/singularity/security/advisories/GHSA-6w7g-p4jh-rf92
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sylabs:singularity:*:*:*:*:*:*:*:* singularity >= 3.5.0 <= 3.5.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
singularity edge-community 3.6.0-r0 None fixed
singularity edge-community 3.5.2-r0 None possibly vulnerable
singularity 3.22-community 3.6.0-r0 None fixed
singularity 3.22-community 3.5.2-r0 None possibly vulnerable
singularity 3.21-community 3.6.0-r0 None fixed
singularity 3.20-community 3.6.0-r0 None fixed
singularity 3.19-community 3.6.0-r0 None fixed