CVE-2023-7245
20.02.2024, 11:15
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable
Vendor | Product | Version |
---|---|---|
openvpn | connect | 3.2.0 ≤ 𝑥 < 3.4.4 |
openvpn | connect | 3.2.0 ≤ 𝑥 < 3.4.8 |
openvpn | connect | 3.0.0:beta |
openvpn | connect | 3.0.0:beta |
openvpn | connect | 3.0.1:beta |
openvpn | connect | 3.0.2:beta |
openvpn | connect | 3.1.0:beta |
openvpn | connect | 3.1.0:beta |
openvpn | connect | 3.1.1:beta |
openvpn | connect | 3.1.1:beta |
openvpn | connect | 3.1.2:beta |
openvpn | connect | 3.1.3:beta |
𝑥
= Vulnerable software versions
References