CVE Vulnerabilities

CVE-2021-33027

Insufficient Entropy

Published: Jul 19, 2021 | Modified: Jul 28, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.

Weakness

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Software

Name Vendor Start Version End Version
Singularity Sylabs 1.2.0 (including) 1.2.6 (excluding)
Singularity Sylabs 1.3.0 (including) 1.3.4 (excluding)
Singularity Sylabs 1.4.0 (including) 1.4.4 (excluding)
Singularity Sylabs 1.5.0 (including) 1.5.4 (excluding)
Singularity Sylabs 1.6.0 (including) 1.6.3 (excluding)
Singularity Ubuntu esm-apps/xenial *
Singularity Ubuntu trusty *
Singularity Ubuntu xenial *

Potential Mitigations

References