Log File Exposure in OpenVPN Access Server Installer
CVE-2022-33737
7.5HIGH
What is CVE-2022-33737?
The OpenVPN Access Server installer creates a log file that can be read by any user, which may contain a randomly generated administrative password. This vulnerability is present in versions 2.10.0 and earlier, potentially exposing sensitive information and allowing unauthorized access to administrative functionalities.
Affected Version(s)
OpenVPN Access Server from version 2.10.0 and before 2.11.0