CVE Vulnerabilities

CVE-2022-3512

Published: Oct 28, 2022 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Using warp-cli command add-trusted-ssid, a user was able to disconnect WARP client and bypass the Lock WARP switch feature resulting in Zero Trust policies not being enforced on an affected endpoint.

Affected Software

Name Vendor Start Version End Version
Warp Cloudflare * 2022.8.857.0 (excluding)
Warp Cloudflare * 2022.8.861.0 (excluding)
Warp Cloudflare * 2022.8.936 (excluding)

References