Vulnerability Description
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paramiko | Paramiko | < 2.10.1 |
| Debian | Debian Linux | 9.0 |
| Fedoraproject | Fedora | 34 |
Related Weaknesses (CWE)
References
- https://github.com/paramiko/paramiko/blob/363a28d94cada17f012c1604a3c99c71a2bda0ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00032.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00013.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.paramiko.org/changelog.htmlRelease NotesVendor Advisory
- https://github.com/paramiko/paramiko/blob/363a28d94cada17f012c1604a3c99c71a2bda0ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/03/msg00032.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00013.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/12/msg00020.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://www.paramiko.org/changelog.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2022-24302?
CVE-2022-24302 is a vulnerability with a CVSS score of 5.9 (MEDIUM). In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
How severe is CVE-2022-24302?
CVE-2022-24302 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24302?
Check the references section above for vendor advisories and patch information. Affected products include: Paramiko Paramiko, Debian Debian Linux, Fedoraproject Fedora.