VulnerabilityModified
CVE-2020-19003
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
MEDIUM 5.3EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- liftoffsoftware/gate one
- Source
- cve@mitre.org
References
- https://cwe.mitre.org/data/definitions/290.htmlTechnical Description
- https://github.com/liftoff/GateOne/issues/728Exploit, Issue Tracking, Third Party Advisory
- https://cwe.mitre.org/data/definitions/290.htmlTechnical Description
- https://github.com/liftoff/GateOne/issues/728Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.