VDB
EN

PYSEC-2018-19

상세

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / paramiko
최초 영향 버전: 0 수정 버전: fa29bd8446c8eab237f5187d28787727b4610516
수정 pip install --upgrade 'paramiko>=fa29bd8446c8eab237f5187d28787727b4610516'

참고