Vulnerability Description
By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies) and features such as 'Lock WARP switch'.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | Warp | < 2022.5.227.0 |
Related Weaknesses (CWE)
References
- https://github.com/cloudflare/advisories/security/advisories/GHSA-cg88-vx48-976cPatchThird Party Advisory
- https://github.com/cloudflare/advisories/security/advisories/GHSA-cg88-vx48-976cPatchThird Party Advisory
FAQ
What is CVE-2022-2225?
CVE-2022-2225 is a vulnerability with a CVSS score of 8.1 (HIGH). By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to bypass configured Zero Trust security policies (e.g. Secure Web Gateway policies)...
How severe is CVE-2022-2225?
CVE-2022-2225 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2225?
Check the references section above for vendor advisories and patch information. Affected products include: Cloudflare Warp.