CVE-2021-31606
Published Sep 27, 2021furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
Vendor archive
3 CVEs tagged to vendor openvpn-monitor_project — 0 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.
furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.