Vulnerabilities > Liftoffsoftware

DATE CVE VULNERABILITY TITLE RISK
2021-10-06 CVE-2020-19003 Authentication Bypass by Spoofing vulnerability in Liftoffsoftware Gate ONE 1.2.0
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
network
low complexity
liftoffsoftware CWE-290
5.3
2020-12-27 CVE-2020-35736 Path Traversal vulnerability in Liftoffsoftware Gateone 1.1
GateOne 1.1 allows arbitrary file download without authentication via /downloads/..
network
low complexity
liftoffsoftware CWE-22
7.5
2020-12-14 CVE-2020-20184 OS Command Injection vulnerability in Liftoffsoftware Gateone
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
network
low complexity
liftoffsoftware CWE-78
critical
9.8