QID 997214

Date Published: 2024-02-12

QID 997214: Python (Pip) Security Update for paramiko (GHSA-wqmm-q65g-2hqr)

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Github security advisory GHSA-wqmm-q65g-2hqr for updates and patch information.
    Vendor References

    CVEs related to QID 997214

    Software Advisories
    Advisory ID Software Component Link
    GHSA-wqmm-q65g-2hqr paramiko URL Logo github.com/advisories/GHSA-wqmm-q65g-2hqr