Authentication Bypass Affecting gateone package, versions [0,]
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.13% (50th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-GATEONE-1730573
- published 13 Oct 2021
- disclosed 12 Oct 2021
- credit Zh3-H4ck
Introduced: 12 Oct 2021
CVE-2020-19003 Open this link in a new tabHow to fix?
There is no fixed version for gateone
.
Overview
gateone is a Web-based Terminal Emulator and SSH Client
Affected versions of this package are vulnerable to Authentication Bypass. An attacker can bypass the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
References
CVSS Scores
version 3.1