An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
References
Link | Resource |
---|---|
https://github.com/liftoff/GateOne/issues/728 | Exploit Issue Tracking Third Party Advisory |
https://cwe.mitre.org/data/definitions/290.html | Technical Description |
Configurations
History
No history.
Information
Published : 2021-10-06 13:15
Updated : 2022-09-14 20:33
NVD link : CVE-2020-19003
Mitre link : CVE-2020-19003
JSON object : View
Products Affected
liftoffsoftware
- gate_one
CWE
CWE-290
Authentication Bypass by Spoofing