PT-2022-21746 · Cloudflare · Cloudflare Warp

Josh

+1

·

Published

2022-10-28

·

Updated

2022-11-01

·

CVE-2022-3321

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Cloudflare WARP iOS mobile client (affected versions not specified)
Description The issue allowed users to bypass the Lock WARP switch feature on the WARP iOS mobile client. This was possible by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches simultaneously in the application settings, causing the WARP client to disconnect. As a result, users could bypass restrictions and policies enforced by the Zero Trust platform.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-3321
GHSA-4463-5P9M-3C78

Affected Products

Cloudflare Warp