Описание
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Отчет
This flaw is a user authentication bypass in the SSH Server functionality of paramiko (normally used by subclassing paramiko.ServerInterface). Where paramiko is used only for its client-side functionality (e.g. paramiko.SSHClient), the vulnerability is not exposed and thus cannot be exploited.
The following Red Hat products use paramiko only in client-side mode. Server side functionality is not used.
- Red Hat Ansible Engine 2
- Red Hat Ceph Storage 2
- Red Hat CloudForms 4
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Virtualization
- Red Hat Gluster Storage 3
- Red Hat Openshift Container Platform
- Red Hat Quick Cloud Installer
- Red Hat Satellite 6
- Red Hat Storage Console 2
- Red Hat OpenStack Platform
- Red Hat Update Infrastructure
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5 | python-paramiko | Out of support scope | ||
| Red Hat Ansible Engine 2 | ansible | Will not fix | ||
| Red Hat Ceph Storage 2 | python-paramiko | Affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-paramiko | Will not fix | ||
| Red Hat OpenShift Container Platform 3.2 | python-paramiko | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.3 | python-paramiko | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.4 | python-paramiko | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.5 | python-paramiko | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.6 | python-paramiko | Out of support scope | ||
| Red Hat OpenShift Container Platform 3.7 | python-paramiko | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 con ...
EPSS
9.8 Critical
CVSS3