Vulnerabilities in warp-tech
12 resultsVexday analysis
Warp-tech apresenta footprint reduzido de 5 CVEs sem incidentes de exploração ativa documentada, mas requer atenção à recente publicação (últimos 90 dias) que aponta fragilidade em autenticação (CWE-287). Ausência de vulnerabilidades críticas reduz urgência imediata, porém a concentração em mecanismos de autenticação demanda validação de controles de acesso nos ambientes que utilizam este fornecedor.
CVE-2023-48712HIGHUser authorization bug leading to privilege escalation in warpgateEPSS 0.7%CVE-2023-28113MEDIUMrussh may use insecure Diffie-Hellman keysEPSS 0.6%CVE-2023-37268MEDIUMUser login confusion with SSO in warpgateEPSS 0.5%CVE-2026-63330HIGHWarpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allows Any Authenticated User to Eavesdrop on Terminal SessionsEPSS 0.4%CVE-2026-58491CRITICALWarpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameterEPSS 0.3%CVE-2023-43660MEDIUMSSH key password bypassed in warpgateEPSS 0.3%CVE-2026-63329MEDIUMWarpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Spoofing to WebSocket Backend TargetsEPSS 0.2%CVE-2026-91164MEDIUMWarpgate: API tokens bypass the user's allowed_ip_ranges restrictionEPSS 0.2%CVE-2026-91167MEDIUMWarpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allows any admin to bypass the `AccessRolesAssign` permission boundaryEPSS 0.2%CVE-2026-91165LOWWarpgate: Markup injection in SSO form_post return page via unencoded redirect/error valuesEPSS 0.2%CVE-2026-91166MEDIUMWarpgate: Web SSH stores a jump host's key against the target's address, so it validates as the targetEPSS 0.2%CVE-2026-44347MEDIUMWarpgate: SSO CSRF -- State Token Not Validated on ReturnEPSS 0.1%