We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-37268

User login confusion with SSO in warpgate



Description

Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user with SSO enabled an attacker may authenticate as an other user. Any user account which does not have a second factor enabled could be compromised. This issue has been addressed in commit `8173f6512a` and in releases starting with version 0.7.3. Users are advised to upgrade. Users unable to upgrade should require their users to use a second factor in authentication.

Reserved 2023-06-29 | Published 2023-07-14 | Updated 2024-10-18 | Assigner GitHub_M


MEDIUM: 6.4CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

Problem types

CWE-287: Improper Authentication

Product status

< 0.7.3
affected

References

github.com/...rpgate/security/advisories/GHSA-868r-97g5-r9g4

github.com/...ommit/8173f6512ab6183fa5edc5c9a5f3760b8979271e

cve.org (CVE-2023-37268)

nvd.nist.gov (CVE-2023-37268)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-37268

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.