Lucene search

K
osvGoogleOSV:GHSA-WQMM-Q65G-2HQR
HistoryMay 01, 2022 - 11:28 p.m.

Paramiko Unsafe randomness usage may allow access to sensitive information

2022-05-0123:28:57
Google
osv.dev
5
paramiko
unsafe randomness
sensitive information

AI Score

6.6

Confidence

Low

EPSS

0.007

Percentile

80.2%

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

References

AI Score

6.6

Confidence

Low

EPSS

0.007

Percentile

80.2%