Описание
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
A flaw in OpenVPN Access Server allows remote attackers to smuggle HTTP requests when the server operates behind a reverse proxy. The issue stems from the server accepting unstandardized bare line-feed sequences in HTTP headers.
Отчет
A Moderate flaw in OpenVPN Access Server allows remote HTTP request smuggling when deployed behind a reverse proxy. This occurs because the server improperly accepts bare line-feed sequences in HTTP headers, causing proxy misinterpretation.
Меры по смягчению последствий
To mitigate this issue, ensure that any reverse proxy deployed in front of OpenVPN Access Server is configured to strictly validate and normalize HTTP header fields, specifically rejecting or sanitizing bare line-feed sequences. Alternatively, consider restricting direct network access to the OpenVPN Access Server, bypassing the reverse proxy, if your deployment architecture allows for it without compromising other security requirements. Consult your reverse proxy's documentation for specific configuration options related to HTTP header parsing and normalization. Any changes to proxy configurations may require a service reload or restart to take effect, which could temporarily interrupt service.
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
EPSS
5.3 Medium
CVSS3