Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

Paramiko not properly checking authentication before processing other requests

GHSA-232r-66cg-79px · CVE-2018-7750 · PYSEC-2018-19

Published · Modified

Description

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes