{"api_version":"1","generated_at":"2026-07-23T15:30:00+00:00","cve":"CVE-2020-19003","urls":{"html":"https://cve.report/CVE-2020-19003","api":"https://cve.report/api/cve/CVE-2020-19003.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-19003","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-19003"},"summary":{"title":"CVE-2020-19003","description":"An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-10-06 13:15:00","updated_at":"2022-09-14 20:33:00"},"problem_types":["CWE-290"],"metrics":[],"references":[{"url":"https://github.com/liftoff/GateOne/issues/728","name":"https://github.com/liftoff/GateOne/issues/728","refsource":"MISC","tags":[],"title":"Gate One Whitelist Bypass · Issue #728 · liftoff/GateOne · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://cwe.mitre.org/data/definitions/290.html","name":"https://cwe.mitre.org/data/definitions/290.html","refsource":"MISC","tags":[],"title":"CWE -\r\n\n\t\tCWE-290: Authentication Bypass by Spoofing (4.3)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-19003","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-19003","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"19003","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liftoffsoftware","cpe5":"gate_one","cpe6":"1.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-19003","qid":"980423","title":"Python (pip) Security Update for gateone (GHSA-q6j2-g8qf-wvf7)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-19003","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/liftoff/GateOne/issues/728","refsource":"MISC","name":"https://github.com/liftoff/GateOne/issues/728"},{"refsource":"MISC","name":"https://cwe.mitre.org/data/definitions/290.html","url":"https://cwe.mitre.org/data/definitions/290.html"}]}},"nvd":{"publishedDate":"2021-10-06 13:15:00","lastModifiedDate":"2022-09-14 20:33:00","problem_types":["CWE-290"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:liftoffsoftware:gate_one:1.2.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"19003","Ordinal":"180412","Title":"CVE-2020-19003","CVE":"CVE-2020-19003","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"19003","Ordinal":"1","NoteData":"An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"19003","Ordinal":"2","NoteData":"2021-10-06","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"19003","Ordinal":"3","NoteData":"2021-10-06","Type":"Other","Title":"Modified"}]}}}