CVE-2023-0654
Last modified
CVE-2023-0654 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and managed to install it on a victim's device, the attacker would be able to trick the user into believing that the app shown on the screen was the WARP client when in reality it was the attacker's app. . EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and managed to install it on a victim's device, the attacker would be able to trick the user into believing that the app shown on the screen was the WARP client when in reality it was the attacker's app.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | Warp | < 6.29 |
References
- https://github.com/cloudflare/advisories/security/advisories/GHSA-5r97-pqv6-xpx7Third Party Advisory
- https://github.com/cloudflare/advisories/security/advisories/GHSA-5r97-pqv6-xpx7Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-0654?
How severe is CVE-2023-0654?
How do I fix CVE-2023-0654?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-0647A vulnerability, which was classified as critical, has been …7.5
- CVE-2023-0648A vulnerability, which was classified as critical, was found…7.5
- CVE-2023-0649A vulnerability has been found in dst-admin 1.5.0 and classi…7.5
- CVE-2023-0650A vulnerability was found in YAFNET up to 3.1.11 and classif…5.4
- CVE-2023-0651A vulnerability was found in FastCMS 0.1.0. It has been clas…9.8
- CVE-2023-0652Due to a hardlink created in the ProgramData folder during t…7.8
- CVE-2023-0655SonicWall Email Security contains a vulnerability that could…5.3
- CVE-2023-0656A Stack-based buffer overflow vulnerability in the SonicOS a…7.5
- CVE-2023-0657A flaw was found in Keycloak. This issue occurs due to impro…3.4
- CVE-2023-0658A vulnerability, which was classified as critical, was found…7.5
- CVE-2023-0659A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has…7.5
- CVE-2023-0660The Smart Slider 3 WordPress plugin before 3.5.1.14 does not…5.4
Are you affected by CVE-2023-0654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
