CVE-2022-24302
published 2022-03-17CVE-2022-24302: In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
2.08%
79.4th percentile
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | paramiko | < paramiko 2.10.3-1 (bookworm) | paramiko 2.10.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paramiko | paramiko | < 2.10.1 | 2.10.1 |
| paramiko | paramiko | >= 0 < 2.7.2-1+deb11u1 | 2.7.2-1+deb11u1 |
| paramiko | paramiko | >= 0 < 2.10.3-1 | 2.10.3-1 |
| paramiko | paramiko | >= 0 < 2.10.3-1 | 2.10.3-1 |
| paramiko | paramiko | >= 0 < 2.10.3-1 | 2.10.3-1 |
| paramiko | paramiko | >= 2.10.0 < 2.10.1 | 2.10.1 |
| paramiko | paramiko | >= 2.9.0 < 2.9.3 | 2.9.3 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Race Condition in Paramiko
osv·2022-03-19
CVE-2022-24302 [HIGH] Race Condition in Paramiko
Race Condition in Paramiko
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
GHSA
Race Condition in Paramiko
ghsa·2022-03-19
CVE-2022-24302 [HIGH] CWE-362 Race Condition in Paramiko
Race Condition in Paramiko
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
OSV
CVE-2022-24302: In Paramiko before 2
osv·2022-03-17·CVSS 5.9
CVE-2022-24302 [MEDIUM] CVE-2022-24302: In Paramiko before 2
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
Ubuntu
Paramiko vulnerability
vendor_ubuntu·2022-03-29
CVE-2022-24302 Paramiko vulnerability
Title: Paramiko vulnerability
Summary: Paramiko would allow unintended access to private key files.
USN-5351-1 fixed a vulnerability in Paramiko. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Jan Schejbal discovered that Paramiko incorrectly handled permissions when
writing private key files. A local attacker could possibly use this issue
to gain access to private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Paramiko vulnerability
vendor_ubuntu·2022-03-28
CVE-2022-24302 Paramiko vulnerability
Title: Paramiko vulnerability
Summary: Paramiko would allow unintended access to private key files.
Jan Schejbal discovered that Paramiko incorrectly handled permissions when
writing private key files. A local attacker could possibly use this issue
to gain access to private keys.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-paramiko: Race condition in the write_private_key_file function
vendor_redhat·2022-03-18·CVSS 5.9
CVE-2022-24302 [MEDIUM] CWE-362 python-paramiko: Race condition in the write_private_key_file function
python-paramiko: Race condition in the write_private_key_file function
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
A race condition was found in Paramiko. This flaw allows unauthorized information disclosure from an attacker with access to the write_private_key_file.
Package: paramiko (Red Hat Ansible Automation Platform 2) - Not affected
Package: python-paramiko (Red Hat Ceph Storage 2) - Out of support scope
Package: python-paramiko (Red Hat Enterprise Linux 6) - Out of support scope
Package: python-paramiko (Red Hat Enterprise Linux 7) - Out of support scope
Package: python-paramiko (Red Hat Storage 3) - Will not fix
Package: python-paramiko (Red Hat Update Infras
Debian
CVE-2022-24302: paramiko - In Paramiko before 2.10.1, a race condition (between creation and chmod) in the ...
vendor_debian·2022·CVSS 5.9
CVE-2022-24302 [MEDIUM] CVE-2022-24302: paramiko - In Paramiko before 2.10.1, a race condition (between creation and chmod) in the ...
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
Scope: local
bookworm: resolved (fixed in 2.10.3-1)
bullseye: resolved (fixed in 2.7.2-1+deb11u1)
forky: resolved (fixed in 2.10.3-1)
sid: resolved (fixed in 2.10.3-1)
trixie: resolved (fixed in 2.10.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/paramiko/paramiko/blob/363a28d94cada17f012c1604a3c99c71a2bda003/paramiko/pkey.py#L546https://lists.debian.org/debian-lts-announce/2022/03/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LUEUEGILZ7MQXRSUF5VMMO4SWJQVPTQL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPMKRUS4HO3P7NR7P4Y6CLHB4MBEE3AI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U63MJ2VOLLQ35R7CYNREUHSXYLWNPVSB/https://www.paramiko.org/changelog.htmlhttps://github.com/paramiko/paramiko/blob/363a28d94cada17f012c1604a3c99c71a2bda003/paramiko/pkey.py#L546https://lists.debian.org/debian-lts-announce/2022/03/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2022/09/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2025/12/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LUEUEGILZ7MQXRSUF5VMMO4SWJQVPTQL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPMKRUS4HO3P7NR7P4Y6CLHB4MBEE3AI/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U63MJ2VOLLQ35R7CYNREUHSXYLWNPVSB/https://www.paramiko.org/changelog.html
2022-03-17
Published