CVE-2020-35736: Liftoffsoftware Gateone
High severity, CVSS 7.5. EPSS: 15.4% chance of exploitation in the next 30 days.
GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.
Affected products
- Liftoffsoftware Gateone: version 1.1 only
Published 2020-12-27. Last modified 2026-06-17.