Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24302

Опубликовано: 18 мар. 2022
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.

A race condition was found in Paramiko. This flaw allows unauthorized information disclosure from an attacker with access to the write_private_key_file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2paramikoNot affected
Red Hat Ceph Storage 2python-paramikoOut of support scope
Red Hat Enterprise Linux 6python-paramikoOut of support scope
Red Hat Enterprise Linux 7python-paramikoOut of support scope
Red Hat Storage 3python-paramikoAffected
Red Hat Update Infrastructure 4 for Cloud Providerspython-paramikoWill not fix
Red Hat OpenStack Platform 16.1python-paramikoFixedRHSA-2022:886307.12.2022
Red Hat OpenStack Platform 16.2python-paramikoFixedRHSA-2022:884507.12.2022
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8python-paramikoFixedRHSA-2022:471226.05.2022
Red Hat Virtualization Engine 4.4python-paramikoFixedRHSA-2022:471226.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2065665python-paramiko: Race condition in the write_private_key_file function

EPSS

Процентиль: 76%
0.01003
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 3 лет назад

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.

CVSS3: 5.9
nvd
больше 3 лет назад

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.

CVSS3: 5.9
debian
больше 3 лет назад

In Paramiko before 2.10.1, a race condition (between creation and chmo ...

suse-cvrf
больше 3 лет назад

Security update for python-paramiko

suse-cvrf
больше 3 лет назад

Security update for python-paramiko

EPSS

Процентиль: 76%
0.01003
Низкий

5.1 Medium

CVSS3