Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| paramiko(PyPI) | 2.4.0 | 2.4.2 | N/A |
| paramiko(PyPI) | 2.3.0 | 2.3.3 | N/A |
| paramiko(PyPI) | 2.2.0 | 2.2.4 | N/A |
| paramiko(PyPI) | 2.1.0 | 2.1.6 | N/A |
| paramiko(PyPI) | 1.5.1 | 2.0.9 | N/A |
CVSS Metrics