Lucene search

K
osvGoogleOSV:USN-5351-1
HistoryMar 28, 2022 - 4:43 p.m.

paramiko vulnerability

2022-03-2816:43:01
Google
osv.dev
12
paramiko
vulnerability
private key
permissions
local attacker
software

AI Score

6.6

Confidence

Low

EPSS

0.003

Percentile

65.5%

Jan Schejbal discovered that Paramiko incorrectly handled permissions when
writing private key files. A local attacker could possibly use this issue
to gain access to private keys.