Vulnerabilities (CVE)

Filtered by vendor Sylabs
Filtered by product Singularity Container Services Library
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-23538 1 Sylabs 1 Singularity Container Services Library 2024-11-21 N/A 5.2 MEDIUM
github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-client is used to pull a container image, with authentication, the HTTP Authorization header sent by the client to the library service may be incorrectly leaked to an S3 backing storage provider. This occurs in a specific flow, where the library service redirects the client to a backing S3 storage server, to perform a multi-part concurrent download. D ...

Show More