CRLF Injection Vulnerability in OpenVPN Access Server by OpenVPN
CVE-2017-5868
6.1MEDIUM
What is CVE-2017-5868?
A CRLF injection vulnerability exists in the web interface of OpenVPN Access Server version 2.1.4. This flaw enables remote attackers to inject arbitrary HTTP headers through the use of '%0A' characters in the PATH_INFO, which can lead to session fixation attacks and potentially facilitate HTTP response splitting. Attackers exploiting this vulnerability could manipulate the server’s response, compromising user sessions and the integrity of user data.