Описание
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Ссылки
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия от 2.7.2 (включая) до 3.1.0 (включая)
cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 18%
0.00259
Низкий
7.5 High
CVSS3
Дефекты
CWE-444
Связанные уязвимости
CVSS3: 5.3
redhat
около 2 месяцев назад
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
CVSS3: 7.5
github
около 2 месяцев назад
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
EPSS
Процентиль: 18%
0.00259
Низкий
7.5 High
CVSS3
Дефекты
CWE-444