CVE-2022-24302
MEDIUM
Published Mar 17, 20224y ago · Modified Jun 17, 20262w ago
5.9 CVSS 3.1
Published Mar 17, 2022 4y ago
Last Modified Jun 17, 2026 2w ago
Description
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None
Threat Intelligence
No active exploitation signals — not in CISA KEV and no EPSS score yet.
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-362
Affected Products 6
| Vendor | Product | Version | Range |
|---|---|---|---|
| paramiko | paramiko | * | <2.10.1 |
| debian | debian_linux | 9.0 | any |
| debian | debian_linux | 10.0 | any |
| fedoraproject | fedora | 34 | any |
| fedoraproject | fedora | 35 | any |
| fedoraproject | fedora | 36 | any |
References 8
- github.com https://github.com/paramiko/paramiko/blob/363a28d94cada17f012c1604a3c99c71a2bda003/paramiko/pkey.py#L546
- lists.debian.org https://lists.debian.org/debian-lts-announce/2022/03/msg00032.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2022/09/msg00013.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2025/12/msg00020.html
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LUEUEGILZ7MQXRSUF5VMMO4SWJQVPTQL/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TPMKRUS4HO3P7NR7P4Y6CLHB4MBEE3AI/
- lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U63MJ2VOLLQ35R7CYNREUHSXYLWNPVSB/
- paramiko.org https://www.paramiko.org/changelog.html
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.