PT-2023-25871 · Warpgate · Warpgate

M-Ishizuka

·

Publicado

2023-07-14

·

Atualizado

2023-07-28

·

CVE-2023-37268

CVSS v3.1

6.4

Média

VetorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Warpgate versions prior to 0.7.3
Description Warpgate is an SSH, HTTPS, and MySQL bastion host for Linux that does not require special client apps. An issue exists where an attacker may authenticate as another user when logging in as a user with SSO enabled. Any user account without a second factor enabled could be compromised.
Recommendations For versions prior to 0.7.3, upgrade to version 0.7.3 or later to resolve the issue. For users unable to upgrade, require their users to use a second factor in authentication as a temporary workaround.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37268
GHSA-868R-97G5-R9G4

Produtos afetados

Warpgate