Liftoffsoftware's vulnerability footprint centers on Gate One, a web-based terminal and SSH client, where identified issues cluster around authentication mechanisms, path-traversal conditions, and command-injection vulnerabilities in its server-side request handling. These weakness classes reflect the security-critical nature of a remote-access tool that bridges user input to underlying system commands and file access. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liftoffsoftware over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35736HIGH GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused. | Dec 27, 2020 | 7.5 | 41 | NO | YES |
CVE-2020-20184CRITICAL GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection. | Dec 14, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-19003MEDIUM An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list. | Oct 6, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liftoffsoftware.
Media articles that mention a CVE ID that affects a product developed by Liftoffsoftware — matched by CVE ID, not by vendor name.