CVE-2020-19003

An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
References
Link Resource
https://cwe.mitre.org/data/definitions/290.html Technical Description
https://github.com/liftoff/GateOne/issues/728 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:liftoffsoftware:gate_one:1.2.0:*:*:*:*:*:*:*

History

14 Sep 2022, 20:33

Type Values Removed Values Added
References (MISC) https://cwe.mitre.org/data/definitions/290.html - (MISC) https://cwe.mitre.org/data/definitions/290.html - Technical Description

10 Jul 2022, 21:15

Type Values Removed Values Added
CWE CWE-287 CWE-290
References
  • (MISC) https://cwe.mitre.org/data/definitions/290.html -

14 Oct 2021, 19:39

Type Values Removed Values Added
References (MISC) https://github.com/liftoff/GateOne/issues/728 - (MISC) https://github.com/liftoff/GateOne/issues/728 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:liftoffsoftware:gate_one:1.2.0:*:*:*:*:*:*:*
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 5.3

06 Oct 2021, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-06 13:15

Updated : 2023-12-10 14:09


NVD link : CVE-2020-19003

Mitre link : CVE-2020-19003

CVE.ORG link : CVE-2020-19003


JSON object : View

Products Affected

liftoffsoftware

  • gate_one
CWE
CWE-290

Authentication Bypass by Spoofing