[PYSEC-2022-166] paramiko vulnerability
Severity
Medium
Affected Packages
128
Fixed Packages
3
CVEs
1
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
Package | Fixed Version |
---|---|
pkg:pypi/paramiko | = 2.9.3 |
pkg:pypi/paramiko | = 2.9.3 |
pkg:pypi/paramiko | = 2.9.3 |
- ID
- PYSEC-2022-166
- Severity
- medium
- Severity from
- CVE-2022-24302
- URL
- https://github.com/advisories/GHSA-f8q4-jwww-x3wv
- Published
-
2022-03-17T22:15:00
(2 years ago) - Modified
-
2022-05-17T03:06:38
(2 years ago) - Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
WEB | https://www.paramiko.org/changelog.html | ||
WEB | https://github.com/paramiko/paramiko/blob/363a28d94cada17f012c1604a3c99c71a2bda003/paramiko/pkey.py#L546 | ||
ADVISORY | GHSA-f8q4-jwww-x3wv | https://github.com/advisories/GHSA-f8q4-jwww-x3wv |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:pypi/paramiko | paramiko | = 2.9.3 | ||||
Fixed | pkg:pypi/paramiko | paramiko | = 2.9.3 | ||||
Fixed | pkg:pypi/paramiko | paramiko | = 2.9.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | >= 2.10.0 < 2.9.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 0.1-bulbasaur | ||||
Affected | pkg:pypi/paramiko | paramiko | = 0.1-charmander | ||||
Affected | pkg:pypi/paramiko | paramiko | = 0.9-doduo | ||||
Affected | pkg:pypi/paramiko | paramiko | = 0.9-eevee | ||||
Affected | pkg:pypi/paramiko | paramiko | = 0.9-fearow | ||||
Affected | pkg:pypi/paramiko | paramiko | = 0.9-gyarados | ||||
Affected | pkg:pypi/paramiko | paramiko | = 0.9-horsea | ||||
Affected | pkg:pypi/paramiko | paramiko | = 0.9-ivysaur | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.10.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.10.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.10.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.10.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.10.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.10.5 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.10.6 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.10.7 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.11.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.11.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.11.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.11.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.11.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.11.5 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.11.6 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.12.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.12.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.12.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.12.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.12.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.13.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.13.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.13.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.13.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.13.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.14.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.14.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.14.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.14.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.15.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.15.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.15.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.15.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.15.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.15.5 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.16.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.16.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.16.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.16.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.17.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.17.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.17.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.17.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.17.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.17.5 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.17.6 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.18.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.18.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.18.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.18.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.18.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.18.5 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.3.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.5.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.5.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.5.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.6 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.6.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.6.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.6.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.6.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.7 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.7.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.7.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.7.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.7.5 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.7.6 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.7.7.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.7.7.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.8.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.8.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 1.9.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.5 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.6 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.7 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.8 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.0.9 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.1.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.1.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.1.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.1.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.1.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.1.5 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.1.6 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.10.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.2.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.2.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.2.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.2.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.2.4 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.3.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.3.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.3.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.3.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.4.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.4.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.4.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.4.3 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.5.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.5.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.6.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.7.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.7.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.7.2 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.8.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.8.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.9.0 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.9.1 | ||||
Affected | pkg:pypi/paramiko | paramiko | = 2.9.2 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |