CyberRota Analysis
AI-GeneratedWarpgate versions prior to 0.25.5 are vulnerable to a critical security flaw that allows attackers to inject malicious markup and JavaScript through an unvalidated parameter in the SSO authentication process, potentially compromising session data and user actions. This vulnerability also facilitates open redirects, which can further expose users to phishing attacks. Organizations using Warpgate for SSH, HTTPS, or MySQL access should prioritize upgrading to version 0.25.5 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by warpgate-protocol-http/src/api/sso_provider_list.rs. A victim who follows a crafted link and completes SSO can cause markup and JavaScript to execute in the authenticated Warpgate origin, allowing access to session data and actions through user APIs, and through administrator APIs only when the victim is an administrator. The GET /@warpgate/api/sso/return path also uses the same unvalidated value as a redirect destination, enabling an open redirect. This issue is fixed in version 0.25.5.