Paramiko Authentication Bypass vulnerability
High severity
GitHub Reviewed
Published
Oct 10, 2018
to the GitHub Advisory Database
•
Updated Oct 9, 2024
Package
Affected versions
>= 2.4.0, < 2.4.2
>= 2.3.0, < 2.3.3
>= 2.2.0, < 2.2.4
>= 2.1.0, < 2.1.6
>= 1.5.1, < 2.0.9
Patched versions
2.4.2
2.3.3
2.2.4
2.1.6
2.0.9
Description
Published by the National Vulnerability Database
Oct 8, 2018
Published to the GitHub Advisory Database
Oct 10, 2018
Reviewed
Jun 16, 2020
Last updated
Oct 9, 2024
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
References