CVE-2020-35736: Liftoffsoftware Gateone

High severity, CVSS 7.5. EPSS: 15.4% chance of exploitation in the next 30 days.

GateOne 1.1 allows arbitrary file download without authentication via /downloads/.. directory traversal because os.path.join is misused.

Affected products

Published 2020-12-27. Last modified 2026-06-17.