Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12750
HistoryJan 15, 2019 - 9:21 a.m.

Authentication Bypass

2019-01-1509:21:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.048 Low

EPSS

Percentile

92.7%

paramiko is vulnerable to authentication bypass attacks. The vulnerability exists as the SSH server implementation of paramiko processes requests without waiting for the completion of authentication. This allows attackers to use a customized SSH client that skips authentication and continue its unauthenticated session.

References