CVE-2018-1000805
published 2018-10-08CVE-2018-1000805: Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.41%
90.2th percentile
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | paramiko | < paramiko 2.4.2-0.1 (bookworm) | paramiko 2.4.2-0.1 (bookworm) |
| paramiko | paramiko | — | — |
| paramiko | paramiko | — | — |
| paramiko | paramiko | — | — |
| paramiko | paramiko | — | — |
| paramiko | paramiko | — | — |
| paramiko | paramiko | — | — |
| paramiko | paramiko | — | — |
| paramiko | paramiko | >= 0 < 2.4.2-0.1 | 2.4.2-0.1 |
| paramiko | paramiko | >= 0 < 2.4.2-0.1 | 2.4.2-0.1 |
| paramiko | paramiko | >= 0 < 2.4.2-0.1 | 2.4.2-0.1 |
| paramiko | paramiko | >= 0 < 2.4.2-0.1 | 2.4.2-0.1 |
| paramiko | paramiko | >= 1.5.1 < 2.0.9 | 2.0.9 |
| paramiko | paramiko | >= 2.1.0 < 2.1.6 | 2.1.6 |
| paramiko | paramiko | >= 2.2.0 < 2.2.4 | 2.2.4 |
| paramiko | paramiko | >= 2.3.0 < 2.3.3 | 2.3.3 |
| paramiko | paramiko | >= 2.4.0 < 2.4.2 | 2.4.2 |
| redhat | ansible_tower | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Paramiko vulnerability
vendor_ubuntu·2018-10-22
CVE-2018-1000805 Paramiko vulnerability
Title: Paramiko vulnerability
Summary: Paramiko could allow unintended access to network services.
USN-3796-1 fixed a vulnerability in Paramiko. This update provides the
corresponding update for Ubuntu 18.10.
Original advisory details:
Daniel Hoffman discovered that Paramiko incorrectly handled authentication
when being used as a server. A remote attacker could use this issue to
bypass authentication without any credentials.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Paramiko vulnerability
vendor_ubuntu·2018-10-17
CVE-2018-1000805 Paramiko vulnerability
Title: Paramiko vulnerability
Summary: Paramiko could allow unintended access to network services.
Daniel Hoffman discovered that Paramiko incorrectly handled authentication
when being used as a server. A remote attacker could use this issue to
bypass authentication without any credentials.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
Paramiko vulnerability
vendor_ubuntu·2018-10-17
CVE-2018-1000805 Paramiko vulnerability
Title: Paramiko vulnerability
Summary: Paramiko could allow unintended access to network services.
USN-3796-1 fixed a vulnerability in paramiko. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Daniel Hoffman discovered that Paramiko incorrectly handled authentication
when being used as a server. A remote attacker could use this issue to
bypass authentication without any credentials.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
python-paramiko: Authentication bypass in auth_handler.py
vendor_redhat·2018-09-07·CVSS 8.8
CVE-2018-1000805 [HIGH] CWE-305 python-paramiko: Authentication bypass in auth_handler.py
python-paramiko: Authentication bypass in auth_handler.py
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Statement: This flaw is a user authentication bypass in the SSH Server functionality of paramiko (normally used by subclassing `paramiko.ServerInterface`). Where paramiko is used only for its client-side functionality (e.g. `paramiko.SSHClient`), the vulnerability is not exposed and thus cannot be exploited.
The following Red Hat products use paramiko only in client-side mode. Server side functionality is not used.
* Red Hat Ansible Engine 2
* Red Hat Ceph Storage 2
* Red Hat CloudForms 4
* Red Hat Enterprise Linux 7
Debian
CVE-2018-1000805: paramiko - Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a In...
vendor_debian·2018·CVSS 8.8
CVE-2018-1000805 [HIGH] CVE-2018-1000805: paramiko - Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a In...
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Scope: local
bookworm: resolved (fixed in 2.4.2-0.1)
bullseye: resolved (fixed in 2.4.2-0.1)
forky: resolved (fixed in 2.4.2-0.1)
sid: resolved (fixed in 2.4.2-0.1)
trixie: resolved (fixed in 2.4.2-0.1)
OSV
Paramiko Authentication Bypass vulnerability
osv·2018-10-10
CVE-2018-1000805 [HIGH] Paramiko Authentication Bypass vulnerability
Paramiko Authentication Bypass vulnerability
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
GHSA
Paramiko Authentication Bypass vulnerability
ghsa·2018-10-10
CVE-2018-1000805 [HIGH] CWE-732 Paramiko Authentication Bypass vulnerability
Paramiko Authentication Bypass vulnerability
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
OSV
CVE-2018-1000805: Paramiko version 2
osv·2018-10-08·CVSS 8.8
CVE-2018-1000805 [HIGH] CVE-2018-1000805: Paramiko version 2
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py
bugzilla·2018-10-09·CVSS 8.8
CVE-2018-1000805 [HIGH] CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py
CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py
Python Paramiko through versions 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5 and 1.17.6 is vulnerable to an authentication bypass in paramiko/auth_handler.py. A remote attacker could exploit this vulnerability in paramiko SSH servers to execute arbitrary code.
Upstream Issue:
https://github.com/paramiko/paramiko/issues/1283
Upstream Patch:
https://github.com/paramiko/paramiko/commit/56c96a65
Discussion:
Created python-paramiko tracking bugs for this issue:
Affects: epel-all [bug 1637265]
Affects: fedora-all [bug 1637264]
Affects: openstack-rdo [bug 1637266]
---
OpenStack consumes the version of paramiko provided by RHEL. However, as per the statement, OpenStack does not use the SSH server functionality of
Bugzilla
CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [fedora-all]
bugzilla·2018-10-09·CVSS 8.8
CVE-2018-1000805 [HIGH] CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [fedora-all]
CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [openstack-rdo]
bugzilla·2018-10-09·CVSS 8.8
CVE-2018-1000805 [HIGH] CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [openstack-rdo]
CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
CVE fixed in paramiko 2
Bugzilla
CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [epel-all]
bugzilla·2018-10-09·CVSS 8.8
CVE-2018-1000805 [HIGH] CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [epel-all]
CVE-2018-1000805 python-paramiko: Authentication bypass in auth_handler.py [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
https://access.redhat.com/errata/RHBA-2018:3497https://access.redhat.com/errata/RHSA-2018:3347https://access.redhat.com/errata/RHSA-2018:3406https://access.redhat.com/errata/RHSA-2018:3505https://github.com/paramiko/paramiko/issues/1283https://herolab.usd.de/wp-content/uploads/sites/4/usd20180023.txthttps://lists.debian.org/debian-lts-announce/2018/10/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00025.htmlhttps://usn.ubuntu.com/3796-1/https://usn.ubuntu.com/3796-2/https://usn.ubuntu.com/3796-3/https://access.redhat.com/errata/RHBA-2018:3497https://access.redhat.com/errata/RHSA-2018:3347https://access.redhat.com/errata/RHSA-2018:3406https://access.redhat.com/errata/RHSA-2018:3505https://github.com/paramiko/paramiko/issues/1283https://herolab.usd.de/wp-content/uploads/sites/4/usd20180023.txthttps://lists.debian.org/debian-lts-announce/2018/10/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00025.htmlhttps://usn.ubuntu.com/3796-1/https://usn.ubuntu.com/3796-2/https://usn.ubuntu.com/3796-3/
2018-10-08
Published