← Back to CVE List

CVE-2017-5868

Published: 2017-05-26T01:29Z
Last Modified: 2024-11-21T03:28Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters in the PATH_INFO to __session_start__/. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt