High severity7.5NVD Advisory· Published Dec 18, 2019· Updated Jun 17, 2026
CVE-2019-19724
CVE-2019-19724
Description
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/sylabs/singularityGo | >= 3.3.0, < 3.5.2 | 3.5.2 |
Affected products
5- Singularity/Singularitydescription
- ghsa-coords3 versionspkg:golang/github.com/sylabs/singularitypkg:rpm/opensuse/singularity&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/singularity&distro=openSUSE%20Tumbleweed
>= 3.3.0, < 3.5.2+ 2 more
- (no CPE)range: >= 3.3.0, < 3.5.2
- (no CPE)range: < 2.6.1-lp151.2.3.1
- (no CPE)range: < 3.8.3-1.2
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-mj73-5x75-9phhghsaADVISORY
- github.com/sylabs/singularity/releases/tag/v3.5.2nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-19724ghsaADVISORY
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.htmlnvdWEB
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.htmlnvdWEB
- github.com/sylabs/singularity/commit/2cda4981812c29f0fb11d3ea6aaf6139f665a631ghsaWEB
News mentions
0No linked articles in our index yet.