Any WARP User Can Access Organization-Specific Application
Team Summary
Official summary from Cloudflare Public Bug Bounty
This was internally reviewed and it was determined that there is no security issue here. First of all, the policy that was set set does exactly what it supposed to do. If you configure an Access policy to allow all clients that pass the WARP check, any client connected to WARP (even the free WARP or another organization's Zero Trust WARP) will have access. This is intended behavior for the "Warp" selector. What has been reported here can be achieved using the 'Gateway' selector - as explained in this tutorial: `https://community.cloudflare.com/t/using-warp-posture-checks-with-cloudflare-access/449569`
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Authentication - Generic