Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-232r-66cg-79px

Опубликовано: 12 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Paramiko not properly checking authentication before processing other requests

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Пакеты

Наименование

paramiko

pip
Затронутые версииВерсия исправления

>= 2.0.0, < 2.0.8

2.0.8

Наименование

paramiko

pip
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.5

2.1.5

Наименование

paramiko

pip
Затронутые версииВерсия исправления

>= 2.2.0, < 2.2.3

2.2.3

Наименование

paramiko

pip
Затронутые версииВерсия исправления

>= 2.3.0, < 2.3.2

2.3.2

Наименование

paramiko

pip
Затронутые версииВерсия исправления

= 2.4.0

2.4.1

Наименование

paramiko

pip
Затронутые версииВерсия исправления

>= 1.18.0, < 1.18.5

1.18.5

Наименование

paramiko

pip
Затронутые версииВерсия исправления

< 1.17.6

1.17.6

EPSS

Процентиль: 94%
0.16054
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
redhat
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
nvd
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

CVSS3: 9.8
debian
больше 7 лет назад

transport.py in the SSH server implementation of Paramiko before 1.17. ...

suse-cvrf
больше 7 лет назад

Security update for python-paramiko

EPSS

Процентиль: 94%
0.16054
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-287