CVE-2022-3320
28.10.2022, 10:15
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint caused the WARP Client to disconnect and allowed bypassing administrative restrictions on a Zero Trust enrolled endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
cloudflare | warp | 𝑥 < 2022.8.857.0 |
cloudflare | warp | 𝑥 < 2022.8.861.0 |
cloudflare | warp | 𝑥 < 2022.8.936 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration