CVE-2019-11328 describes a privilege escalation vulnerability in Singularity versions 3.1.0 to 3.2.0-rc2, affecting products like Fedora and openSUSE. A malicious user with local or network access to the host system can manipulate files within specific Singularity instance directories due to insecure permissions. This manipulation can alter the behavior of the starter-suid program, leading to potential privilege escalation. Rated 8.8 HIGH on CVSS, this vulnerability has a low attack complexity and can result in high impact to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.0, < 3.2.0CPE matchmatch criteria | cpe:2.3:a:sylabs:singularity:*:*:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:sylabs:singularity:3.2.0:-:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:sylabs:singularity:3.2.0:rc1:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:sylabs:singularity:3.2.0:rc2:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.