Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5916
HistoryMar 14, 2018 - 3:11 a.m.

Authentication Bypass

2018-03-1403:11:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.048 Low

EPSS

Percentile

92.7%

paramiko is vulnerable to authentication bypass attacks. The vulnerability exists as the SSH server implementation of paramiko processes requests without waiting for the completion of authentication. This allows attackers to use a customized SSH client that skips authentication and continue its unauthenticated session.