CVE detail
CVE-2008-0299 — CVE-2008-0299
Published 2008-01-16 · Modified 2026-06-16 · Vendor python_software_foundation · Product paramiko · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0162
EPSS probability
exploitation probability, 30d
74.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References