Vulnerabilities > Cloudflare > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-21 | CVE-2023-1314 | Link Following vulnerability in Cloudflare Cloudflared A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a local attacker with no administrative permissions to escalate their privileges on the affected device. | 7.8 |
2023-01-11 | CVE-2022-4428 | Improper Input Validation vulnerability in Cloudflare Warp support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send feedback" option. | 8.0 |
2022-10-28 | CVE-2022-3321 | Missing Authorization vulnerability in Cloudflare Warp Mobile Client It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. | 8.2 |
2022-10-28 | CVE-2022-3322 | Improper Verification of Cryptographic Signature vulnerability in Cloudflare Warp Mobile Client Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action. | 7.5 |
2022-10-28 | CVE-2022-3337 | Missing Authorization vulnerability in Cloudflare Warp Mobile Client It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature being enabled on Zero Trust Platform. | 8.5 |
2022-10-28 | CVE-2022-3512 | Unspecified vulnerability in Cloudflare Warp Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced on an affected endpoint. | 8.8 |
2022-10-28 | CVE-2022-3616 | Excessive Iteration vulnerability in Cloudflare Octorpki Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. | 7.5 |
2022-09-30 | CVE-2022-2529 | Resource Exhaustion vulnerability in Cloudflare Goflow sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. | 7.5 |
2022-07-26 | CVE-2022-2225 | Unspecified vulnerability in Cloudflare Warp By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. | 7.8 |
2022-06-28 | CVE-2022-2145 | Link Following vulnerability in Cloudflare Warp Cloudflare WARP client for Windows (up to v. | 7.8 |