CVE Vulnerabilities

CVE-2022-2225

Published: Jul 26, 2022 | Modified: Aug 01, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as Lock WARP switch.

Affected Software

Name Vendor Start Version End Version
Warp Cloudflare * 2022.5.227.0 (excluding)
Warp Cloudflare * 2022.5.341.0 (excluding)
Warp Cloudflare * 2022.5.346 (excluding)

References