Vulnerabilities > Cloudflare

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-1412 Link Following vulnerability in Cloudflare Warp
An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to perform privileged operations with SYSTEM context by working with a combination of opportunistic locks (oplock) and symbolic links (which can both be created by an unprivileged user). After installing the Cloudflare WARP Client (admin privileges required), an MSI-Installer is placed under C:\Windows\Installer.
local
low complexity
cloudflare CWE-59
7.8
2023-03-21 CVE-2023-1314 Link Following vulnerability in Cloudflare Cloudflared
A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a local attacker with no administrative permissions to escalate their privileges on the affected device.
local
low complexity
cloudflare CWE-59
7.8
2023-01-11 CVE-2022-4428 Improper Input Validation vulnerability in Cloudflare Warp
support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send feedback" option.
network
low complexity
cloudflare CWE-20
8.0
2023-01-11 CVE-2022-4457 Unspecified vulnerability in Cloudflare Warp
Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack.
local
low complexity
cloudflare
5.5
2022-12-27 CVE-2014-125026 Out-of-bounds Write vulnerability in Cloudflare Golz4
LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.
network
low complexity
cloudflare CWE-787
critical
9.8
2022-10-28 CVE-2022-3320 Missing Authorization vulnerability in Cloudflare Warp
It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand.
network
low complexity
cloudflare CWE-862
critical
9.8
2022-10-28 CVE-2022-3321 Missing Authorization vulnerability in Cloudflare Warp Mobile Client
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings.
network
low complexity
cloudflare CWE-862
8.2
2022-10-28 CVE-2022-3322 Improper Verification of Cryptographic Signature vulnerability in Cloudflare Warp Mobile Client
Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action.
network
low complexity
cloudflare CWE-347
7.5
2022-10-28 CVE-2022-3337 Missing Authorization vulnerability in Cloudflare Warp Mobile Client
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  feature being enabled on Zero Trust Platform.
network
low complexity
cloudflare CWE-862
8.5
2022-10-28 CVE-2022-3512 Unspecified vulnerability in Cloudflare Warp
Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint.
network
low complexity
cloudflare
8.8