Paramiko Unsafe randomness usage may allow access to sensitive information
High severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Oct 8, 2024
Description
Published by the National Vulnerability Database
Jan 16, 2008
Published to the GitHub Advisory Database
May 1, 2022
Reviewed
Feb 9, 2024
Last updated
Oct 8, 2024
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
References