CVE-2018-7750

Source
https://cve.org/CVERecord?id=CVE-2018-7750
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7750.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-7750
Aliases
Downstream
Related
Published
2018-03-13T18:29:00.303Z
Modified
2026-02-12T08:24:19.849908Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

References

Affected packages

Git / github.com/ansible/ansible

Affected versions

v2.*
v2.2.0.0-1
v2.2.1.0-0.1.rc1
v2.2.1.0-0.2.rc2
v2.2.1.0-0.3.rc3
v2.2.1.0-0.4.rc4
v2.2.1.0-0.5.rc5
v2.2.1.0-1
v2.2.2.0-0.1.rc1
v2.2.2.0-0.2.rc2
v2.2.2.0-1
v2.2.3.0-0.1.rc1
v2.3.0.0-1
v2.3.1.0-0.1.rc1
v2.3.1.0-0.2.rc2
v2.3.1.0-1
v2.3.2.0-0.1.rc1
v2.3.2.0-0.2.rc2
v2.3.2.0-0.3.rc3
v2.3.2.0-0.4.rc4
v2.3.2.0-0.5.rc5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7750.json"

Git / github.com/paramiko/paramiko

Affected versions

1.*
1.16.2
1.16.3
1.17.1
1.17.2
1.17.3
1.17.4
1.17.5
1.17.6
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
v1.*
v1.16.2
v1.16.3
v1.17.1
v1.17.2
v1.17.3
v1.18.0
v1.18.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7750.json"