Описание
Paramiko Authentication Bypass vulnerability
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000805
- https://github.com/paramiko/paramiko/issues/1283
- https://access.redhat.com/errata/RHBA-2018:3497
- https://access.redhat.com/errata/RHSA-2018:3347
- https://access.redhat.com/errata/RHSA-2018:3406
- https://access.redhat.com/errata/RHSA-2018:3505
- https://github.com/advisories/GHSA-f2j6-wrhh-v25m
- https://github.com/pypa/advisory-database/tree/main/vulns/paramiko/PYSEC-2018-69.yaml
- https://herolab.usd.de/wp-content/uploads/sites/4/usd20180023.txt
- https://lists.debian.org/debian-lts-announce/2018/10/msg00018.html
- https://lists.debian.org/debian-lts-announce/2021/12/msg00025.html
- https://usn.ubuntu.com/3796-1
- https://usn.ubuntu.com/3796-2
- https://usn.ubuntu.com/3796-3
Пакеты
paramiko
>= 2.4.0, < 2.4.2
2.4.2
paramiko
>= 2.3.0, < 2.3.3
2.3.3
paramiko
>= 2.2.0, < 2.2.4
2.2.4
paramiko
>= 2.1.0, < 2.1.6
2.1.6
paramiko
>= 1.5.1, < 2.0.9
2.0.9
EPSS
8.7 High
CVSS4
8.8 High
CVSS3
CVE ID
Дефекты
Связанные уязвимости
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 con ...
EPSS
8.7 High
CVSS4
8.8 High
CVSS3