View all vulnerabilities

CVE-2022-24302

Race Condition in Paramiko

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
5.8
Score Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Versions
paramiko >= 2.10.0 < 2.10.1; paramiko >= 2.9.0 < 2.9.3
Severity
Medium
Ecosystem
Python
Publish Date
March 18, 2022
Modified Date
October 9, 2024