CyberRota Analysis
AI-GeneratedOpenVPN Access Server versions 2.7.2 to 3.1.0 are vulnerable to HTTP request smuggling due to improper handling of bare line-feed sequences in HTTP header values. This flaw can be exploited by remote attackers, potentially leading to unauthorized access or manipulation of requests when the server is behind a reverse proxy. Organizations using these versions should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Related CVEs
Other vulnerabilities affecting the same vendor(s)