{"id":"GHSA-jq42-hfch-42f3","summary":"Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint","details":"# Impact\nDue to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container using a `library://` URI will always attempt to retrieve the container from the default remote endpoint (`cloud.sylabs.io`) rather than the configured remote endpoint.\n\nAn attacker may be able to push a malicious container to the default remote endpoint with a URI that is identical to the URI used by a victim with a non-default remote endpoint, thus executing the malicious container.\n\nOnly action commands (`run`/`shell`/`exec`) against `library://` URIs are affected. Other commands such as `pull` / `push` respect the configured remote endpoint.\n\n# Patches\nAll users should upgrade to Singularity 3.7.4 or later.\n\n# Workarounds\nUsers who only interact with the default remote endpoint or do not use the library:// url are not affected.\n\nInstallations with an execution control list configured to restrict execution to containers signed with specific secure keys are not affected.\n\n# Acknowledgements\nThis issue was found by Mike Frisch and brought to our attention by Sylabs.  Sylabs is making a [coordinated disclosure](https://github.com/sylabs/singularity/security/advisories/GHSA-5mv9-q7fq-9394).\n\n# For more information\nGeneral questions about the impact of the advisory can be asked in the:\n\n[Singularity Slack Channel](https://join.slack.com/t/hpcng/shared_invite/zt-qda4h1ls-OP0Uouq6sSmVE6i_0NrWdw)\n[Singularity Mailing List](https://groups.google.com/a/lbl.gov/g/singularity)\nAny sensitive security concerns should be directed to: [singularity-security@hpcng.org](mailto:singularity-security@hpcng.org)\n","modified":"2021-10-05T17:22:08Z","published":"2021-06-01T21:20:53Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-05-28T20:04:38Z","nvd_published_at":null,"cwe_ids":["CWE-20"]},"references":[{"type":"WEB","url":"https://github.com/hpcng/singularity/security/advisories/GHSA-jq42-hfch-42f3"},{"type":"WEB","url":"https://github.com/sylabs/singularity/security/advisories/GHSA-5mv9-q7fq-9394"},{"type":"PACKAGE","url":"https://github.com/hpcng/singularity"}],"affected":[{"package":{"name":"github.com/hpcng/singularity","ecosystem":"Go","purl":"pkg:golang/github.com/hpcng/singularity"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.7.2"},{"fixed":"3.7.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-jq42-hfch-42f3/GHSA-jq42-hfch-42f3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"}]}