Vulnerabilities > CVE-2022-3320 - Missing Authorization vulnerability in Cloudflare Warp

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
cloudflare
CWE-862
critical

Summary

It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint caused the WARP Client to disconnect and allowed bypassing administrative restrictions on a Zero Trust enrolled endpoint.

Vulnerable Configurations

Part Description Count
Application
Cloudflare
66

Common Weakness Enumeration (CWE)