Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34734
HistoryMar 18, 2022 - 5:54 a.m.

Information Disclosure

2022-03-1805:54:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
information disclosure
paramiko
pkey.py
remote attacker
unauthorized access
system security

EPSS

0.003

Percentile

65.5%

paramiko is vulnerable to information disclosure. The vulnerability exists due to lack of sanitization in write_private_key_file parameter in pkey.py which allows a remote attacker to access unauthorized information in system.