5.9
CVSSv3

CVE-2022-24302

Published: 17/03/2022 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Paramiko prior to 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

paramiko paramiko

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #1008012 paramiko: CVE-2022-24302 Package: src:paramiko; Maintainer for src:paramiko is Debian Python Team <team+python@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 20 Mar 2022 14:45:03 UTC Severity: important Tags: security, upstream Found in version ...
Synopsis Moderate: Red Hat OpenStack Platform 1619 (python-paramiko) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-paramiko is now available for Red Hat OpenStackPlatform 1619 (Tr ...
Synopsis Moderate: RHV Engine and Host Common Packages security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic Updated dependency packages for ovirt-engine and ovirt-host that fix several bugs and add various enhan ...
Synopsis Moderate: Red Hat OpenStack Platform 1624 (python-paramiko) security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-paramiko is now available for Red Hat OpenStackPlatform 1624 (Tr ...
Synopsis Moderate: OpenShift Container Platform 41120 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 41120 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impactof ...
Synopsis Moderate: OpenShift Container Platform 4120 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4120 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Cont ...
In Paramiko before 2101, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure (CVE-2022-24302) ...
In Paramiko before 2101, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure ...