Executive brief
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
Affected products
- PyPI paramiko
Junglewise Threat Intelligence
CVE-2022-24302 · Severity: low · CVSS 3.1 · Published 2022-03-17
Technologies: paramiko (PyPI). Vendors: PyPI.
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.