CVE-2021-29499

SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged to upgrade. As a workaround, users passing CreateInfo struct should ensure the `ID` field is generated using a version of `github.com/satori/go.uuid` that is not vulnerable to this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 59.09%
Affected Products (NVD)
VendorProductVersion
sylabssingularity_image_format
𝑥
< 1.2.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-github-sylabs-sif
bookworm
2.8.3-1
fixed
bullseye
no-dsa
sid
2.19.2-1
fixed
trixie
2.19.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-sylabs-sif
bionic
dne
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needed
oracular
ignored
plucky
ignored
questing
ignored
resolute
needed
trusty
dne
xenial
dne
singularity-container
bionic
needs-triage
focal
dne
jammy
dne
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage
trusty
dne
xenial
dne