Sept. 27, 2023, 10:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be bypassed by sending an SSH key offer without a signature. This allows bypassing authentication under following conditions: 1. The attacker knows the username and a valid target name 2. The attacked knows the user's public key and 3. Only SSH public key authentication is required for the user account. This issue has been …

apps attacker authentication bastion bypassing client conditions cve host https key linux mysql name offer signature smart special ssh ssh key target under username valid verification

Security Architect

@ Alter Solutions | Lisboa, Portugal

Information Security Program Manager

@ Fisher Investments | Tampa, FL, United States

Digital Security Infrastructure Manager

@ Wizz Air | Budapest, HU, H-1103

Sr. Solution Consultant

@ Highspot | Sydney

Cyber Security Analyst III

@ Love's Travel Stops | Oklahoma City, OK, US, 73120

Lead Security Engineer

@ JPMorgan Chase & Co. | Tampa, FL, United States