
liftoff/GateOne
Releases3
Frequency4 months 1 week
Last Release
Stars6.3K
Gate One is an HTML5-powered terminal emulator and SSH client
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 5.3 MEDIUM | 5 MEDIUM | ||
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list. | |||
| 7.5 HIGH | 5 MEDIUM | ||
GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused. | |||
| 9.8 CRITICAL | 7.5 HIGH | ||
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection. | |||