CVE Vulnerabilities

CVE-2023-37268

Improper Authentication

Published: Jul 14, 2023 | Modified: Jul 28, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesnt need special client apps. When logging in as a user with SSO enabled an attacker may authenticate as an other user. Any user account which does not have a second factor enabled could be compromised. This issue has been addressed in commit 8173f6512a and in releases starting with version 0.7.3. Users are advised to upgrade. Users unable to upgrade should require their users to use a second factor in authentication.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Warpgate Warpgate_project 0.7.2 (including) 0.7.2 (including)

Potential Mitigations

References