Skip to content

Lock WARP switch feature bypass on WARP mobile client for iOS

Moderate
mskowroncf published GHSA-4463-5p9m-3c78 Oct 28, 2022

Package

Cloudflare WARP mobile client (iOS)

Affected versions

<6.14

Patched versions

None

Description

Impact

It was possible to bypass Lock WARP switch feature on WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused the WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform.

Patches

The issue was fixed in version 6.14 of the iOS mobile client.

References

Severity

Moderate

CVE ID

CVE-2022-3321

Weaknesses

No CWEs