Warpgate Project

Warpgate

5 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Published 05.08.2025 00:05:20
  • Last modified 13.08.2025 18:32:38

Russh is a Rust SSH client & server library. In versions 0.54.0 and below, the channel window adjust message of the SSH protocol is used to track the free space in the receive buffer of the other side of a channel. The current implementation takes th...

Exploit
  • EPSS 0.58%
  • Published 21.08.2024 16:15:08
  • Last modified 13.08.2025 18:32:43

Russh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to OOM a russh server. An SSH packet consists of a 4-byte big-endian length, followed by a byte stream of this length. After parsing...

  • EPSS 0.21%
  • Published 24.11.2023 17:15:08
  • Last modified 21.11.2024 08:32:18

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. In affected versions there is a privilege escalation vulnerability through a non-admin user's account. Limited users can impersonate another user's account if only single-factor ...

  • EPSS 0.04%
  • Published 27.09.2023 22:15:10
  • Last modified 21.11.2024 08:24:34

Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be bypassed by sending an SSH key offer without a signature. This allows bypassing authentication under fol...

  • EPSS 0.17%
  • Published 14.07.2023 22:15:09
  • Last modified 21.11.2024 08:11:21

Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user with SSO enabled an attacker may authenticate as an other user. Any user account which does not have a second factor enabled c...