← Back

CVE-2022-4428

nvd nist
Published: Jan 11, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: NVD

Description

support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the local machine upon clicking on the "Send feedback" option. An attacker with access to the local file system could use a crafted XML config file pointing to a malicious file or set a local path to the executable using Cloudflare Zero Trust Dashboard (for Zero Trust enrolled clients).

Affected (1)

Products: Cloudflare: Warp
1 product
Warp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2022.10.106.0

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory

Timeline

No history available yet.