PT-2023-25871 · Warpgate · Warpgate
M-Ishizuka
·
Published
2023-07-14
·
Updated
2023-07-28
·
CVE-2023-37268
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Warpgate versions prior to 0.7.3
Description
Warpgate is an SSH, HTTPS, and MySQL bastion host for Linux that does not require special client apps. An issue exists where an attacker may authenticate as another user when logging in as a user with SSO enabled. Any user account without a second factor enabled could be compromised.
Recommendations
For versions prior to 0.7.3, upgrade to version 0.7.3 or later to resolve the issue.
For users unable to upgrade, require their users to use a second factor in authentication as a temporary workaround.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Warpgate