In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-paramiko-docUpgrade python2-paramiko | Sep 28, 2023 | Mar 17, 2022 |
| Centos_linux | — | Upgrade python3-netaddrUpgrade python3-ovirt-engine-sdk4Upgrade python38-ovirt-engine-sdk4-debuginfoUpgrade python-pycurl-debugsourceUpgrade python3-passlibUpgrade python-pycurl-debuginfoUpgrade python3-ovirt-engine-sdk4-debuginfoUpgrade python38-jmespathUpgrade python38-pycurlUpgrade python38-ovirt-imageio-common-debuginfoUpgrade python38-pycurl-debuginfoUpgrade python-ovirt-engine-sdk4-debuginfoUpgrade python38-ovirt-imageio-clientUpgrade python38-ovirt-imageio-commonUpgrade python3-pycurlUpgrade ovirt-imageio-debuginfoUpgrade ovirt-ansible-collectionUpgrade ovirt-imageio-common-debuginfoUpgrade python38-netaddrUpgrade ansible-collection-ansible-posixUpgrade python38-ovirt-engine-sdk4Upgrade ovirt-imageio-debugsourceUpgrade ovirt-imageio-commonUpgrade ansible-collection-ansible-utilsUpgrade ovirt-imageio-clientUpgrade python3-pycurl-debuginfoUpgrade python3-jmespathUpgrade python-ovirt-engine-sdk4-debugsourceUpgrade ansible-collection-ansible-netcommonUpgrade python38-passlib | May 27, 2022 | Mar 17, 2022 |
| Debian | — | Upgrade paramiko | Mar 23, 2022 | Mar 17, 2022 |
| Dell Powerstore Dsa2023129 | — | Upgrade Dell PowerStoreOS to the latest version | Jan 13, 2026 | Apr 4, 2023 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Dell Powerstore Dsa2025182 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Apr 17, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python-paramiko-help.rpmUpgrade python-paramiko-helpUpgrade python3-paramiko | Jun 14, 2022 | Mar 17, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-paramiko | May 25, 2022 | Mar 17, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-paramiko | Jun 17, 2022 | Mar 17, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python2-paramikoUpgrade python3-paramiko | Jun 22, 2022 | Mar 17, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-paramiko | Jun 16, 2022 | Mar 17, 2022 |
| Redhat_linux | — | Upgrade ovirt-ansible-collectionUpgrade python38-ovirt-imageio-clientUpgrade python3-netaddrUpgrade ovirt-imageio-clientUpgrade python3-passlibNo solution existsUpgrade python3-ovirt-engine-sdk4-debuginfoUpgrade python38-ovirt-imageio-commonUpgrade python38-ovirt-imageio-common-debuginfoUpgrade ovirt-imageio-debuginfoUpgrade python38-passlibUpgrade ovirt-imageio-commonUpgrade python3-jmespathUpgrade python-pycurl-debugsourceUpgrade ansible-collection-ansible-posixUpgrade python3-pycurl-debuginfoUpgrade ovirt-imageio-common-debuginfoUpgrade python38-ovirt-engine-sdk4-debuginfoUpgrade ansible-collection-ansible-netcommonUpgrade python3-ovirt-engine-sdk4Upgrade ovirt-imageio-debugsourceUpgrade python-pycurl-debuginfoUpgrade python-ovirt-engine-sdk4-debuginfoUpgrade python38-pycurlUpgrade python38-pycurl-debuginfoUpgrade python3-pycurlUpgrade python38-ovirt-engine-sdk4Upgrade python-ovirt-engine-sdk4-debugsourceUpgrade python38-netaddrUpgrade ansible-collection-ansible-utilsUpgrade python38-jmespath | May 27, 2022 | Mar 17, 2022 |
| Suse | — | Upgrade python2-paramikoUpgrade python-paramikoUpgrade python3-paramikoUpgrade python-paramiko-doc | Oct 26, 2022 | Mar 17, 2022 |
| Ubuntu | — | Upgrade python3-paramikoUpgrade python3-paramiko (Ubuntu Pro)Upgrade paramiko-doc (Ubuntu Pro)Upgrade python-paramikoUpgrade python-paramiko (Ubuntu Pro) | Mar 29, 2022 | Mar 17, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 17, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub