Candidate: CVE-2018-12021 PublicDate: 2018-07-05 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12021 https://github.com/singularityware/singularity/releases/tag/2.5.2 Description: Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific Singularity features. Ubuntu-Description: It was discovered that Singularity incorrectly handled access control. An attacker could possibly use this issue to obtain sensitive information. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_singularity-container: upstream_singularity-container: released (2.5.2-1) precise/esm_singularity-container: DNE trusty_singularity-container: DNE trusty/esm_singularity-container: DNE xenial_singularity-container: DNE artful_singularity-container: ignored (reached end-of-life) bionic_singularity-container: needed cosmic_singularity-container: not-affected (2.5.2-2) disco_singularity-container: not-affected (2.6.1-2) eoan_singularity-container: not-affected (2.6.1-2) focal_singularity-container: DNE groovy_singularity-container: DNE hirsute_singularity-container: DNE impish_singularity-container: DNE jammy_singularity-container: DNE devel_singularity-container: DNE