Skip to main content

Vendor archive

cloudflare CVEs

Beta · best-effort

61 CVEs tagged to vendor cloudflare3 Critical, 23 High, 30 Medium, 5 Low, 0 Unrated.

CVE-2023-0654

Published Aug 29, 2023

Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and mana…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-0238

Published Aug 29, 2023

Due to lack of a security policy, the WARP Mobile Client (<=6.29) for Android was susceptible to this vulnerability which allowed a malicious app installed on a victim's device to…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-4241

Published Aug 16, 2023

lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3766

Published Aug 3, 2023

A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specifically occurs when processing encry…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2754

Published Aug 3, 2023

The Cloudflare WARP client for Windows assigns loopback IPv4 addresses for the DNS Servers, since WARP acts as local DNS server that performs DNS queries in a secure manner, howev…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1862

Published Jun 20, 2023

Cloudflare WARP client for Windows (up to v2023.3.381.0) allowed a malicious actor to remotely access the warp-svc.exe binary due to an insufficient access control policy on an IP…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3040

Published Jun 14, 2023

A debug function in the lua-resty-json package, up to commit id 3ef9492bd3a44d9e51301d6adc3cd1789c8f534a (merged in PR #14) contained an out of bounds access bug that could have a…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-3036

Published Jun 14, 2023

An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b https://github.com/cloudflare/cfnts/commit/783490b913f05e508a492cd7b02e3c4ec2297b71  enable…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2512

Published May 12, 2023

Prior to version v1.20230419.0, the FormData API implementation was subject to an integer overflow. If a FormData instance contained more than 2^31 elements, the forEach() method…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1732

Published May 10, 2023

When sampling randomness for a shared secret, the implementation of Kyber and FrodoKEM, did not check whether crypto/rand.Read() returns an error. In rare deployment cases (error…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0652

Published Apr 6, 2023

Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 2022.12.582.0) allowed a maliciou…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1412

Published Apr 5, 2023

An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to perform privileged operations…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1314

Published Mar 21, 2023

A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a local attacker with no administrative permissions to escalat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4457

Published Jan 11, 2023

Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker could create a malicious mobile ap…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4428

Published Jan 11, 2023

support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privilege escalation and launching an arbitrary executable on the…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2014-125026

Published Dec 27, 2022

LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-3512

Published Oct 28, 2022

Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" feature resulting in Zero Trust policies not being enforced…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3337

Published Oct 28, 2022

It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connectio…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3322

Published Oct 28, 2022

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3321

Published Oct 28, 2022

It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  on the WARP…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3320

Published Oct 28, 2022

It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' subcommand. Using this command with an unreachable endpoint…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3616

Published Oct 28, 2022

Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2529

Published Sep 30, 2022

sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attackers can craft malformed packets causing the process to cons…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2225

Published Jul 26, 2022

By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 61 CVEsPage 2 of 3