High severity7.5NVD Advisory· Published Jul 14, 2020· Updated Jun 17, 2026
CVE-2020-13845
CVE-2020-13845
Description
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/sylabs/singularityGo | >= 3.0.0, < 3.6.0 | 3.6.0 |
Affected products
7- Sylabs/Singularitydescription
- ghsa-coords5 versionspkg:golang/github.com/sylabs/singularitypkg:rpm/opensuse/singularity&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/singularity&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/singularity&distro=openSUSE%20Tumbleweedpkg:rpm/suse/singularity&distro=SUSE%20Package%20Hub%2015%20SP2
>= 3.0.0, < 3.6.0+ 4 more
- (no CPE)range: >= 3.0.0, < 3.6.0
- (no CPE)range: < 3.6.0-lp151.2.6.1
- (no CPE)range: < 3.6.0-lp152.2.3.1
- (no CPE)range: < 3.8.3-1.2
- (no CPE)range: < 3.6.0-bp152.2.4.1
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-pmfr-63c2-jr5cghsaADVISORY
- github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5cnvdThird Party AdvisoryWEB
- medium.com/sylabsnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-13845ghsaADVISORY
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00046.htmlnvdBroken LinkWEB
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.htmlnvdBroken LinkWEB
- lists.opensuse.org/opensuse-security-announce/2020-09/msg00053.htmlnvdBroken LinkWEB
News mentions
0No linked articles in our index yet.