CVE-2022-3322

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cloudflare:warp_mobile_client:*:*:*:*:*:iphone_os:*:*

History

07 Nov 2023, 03:51

Type Values Removed Values Added
Summary Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action. Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action.

31 Oct 2022, 17:10

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://github.com/cloudflare/advisories/security/advisories/GHSA-76pg-rp9h-wmcj - (MISC) https://github.com/cloudflare/advisories/security/advisories/GHSA-76pg-rp9h-wmcj - Third Party Advisory
First Time Cloudflare
Cloudflare warp Mobile Client
CWE CWE-347
CPE cpe:2.3:a:cloudflare:warp_mobile_client:*:*:*:*:*:iphone_os:*:*

28 Oct 2022, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-28 10:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-3322

Mitre link : CVE-2022-3322

CVE.ORG link : CVE-2022-3322


JSON object : View

Products Affected

cloudflare

  • warp_mobile_client
CWE
CWE-347

Improper Verification of Cryptographic Signature

CWE-862

Missing Authorization