Vendor
Liftoffsoftware
Products
2
CVEs
3
Across products
3
Status
Private
Products
2- 2 CVEs
- 1 CVE
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-20184 | Cri | 0.64 | 9.8 | 0.03 | Dec 14, 2020 | GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection. | ||
| CVE-2020-35736 | Hig | 0.50 | 7.5 | 0.15 | Dec 27, 2020 | GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused. | ||
| CVE-2020-19003 | Med | 0.35 | 5.3 | 0.01 | Oct 6, 2021 | An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list. |
- risk 0.64cvss 9.8epss 0.03
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
- risk 0.50cvss 7.5epss 0.15
GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.
- risk 0.35cvss 5.3epss 0.01
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.