漏洞信息详情
Singularity 权限许可和访问控制问题漏洞
漏洞简介
Singularity是一款基于Linux平台的用于独立运行应用程序的容器平台。
Singularity 3.1.0至3.2.0-rc2版本中存在权限许可和访问控制问题漏洞,该漏洞源于网络系统或产品缺乏有效的权限许可和访问控制措施。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/sylabs/singularity/releases/tag/v3.2.0
参考网址
来源:MLIST
链接:http://www.openwall.com/lists/oss-security/2019/05/16/1
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/LNU5BUHFOTYUZVHFUSX2VG4S3RCPUEMA/
来源:BID
链接:https://www.securityfocus.com/bid/108360
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html
来源:github.com
链接:https://github.com/sylabs/singularity/releases/tag/v3.2.0
来源:seclists.org
链接:https://seclists.org/oss-sec/2019/q2/112
来源:www.sylabs.io
链接:https://www.sylabs.io/singularity/
来源:github.com
链接:https://github.com/sylabs/singularity/commit/b4dcb0e4d77baa1c7647a4a5705ea824bb4e0dca
来源:BID
链接:http://www.securityfocus.com/bid/108360
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/5O3TPL5OOTIZEI4H6IQBCCISBARJ6WL3/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/LIHV7DSEVTB5SUPEZ2UXGS3Q6WMEQSO2/
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00028.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/singularity-privilege-escalation-29398
来源:www.securityfocus.com
链接:https://www.securityfocus.com/bid/108360
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-11328
受影响实体
暂无
补丁
- Singularity 权限许可和访问控制问题漏洞的修复措施<!--2019-5-14-->
还没有评论,来说两句吧...