← Back

CVE-2023-7245

nvd nist
Published: Feb 20, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable

Affected (12)

Products: Openvpn: Connect
1 product
Connect
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Openvpn
From 3.2.0 to 3.4.8
From 3.2.0 to 3.4.4
Version 3.0.0 beta
Version 3.0.0 beta
Version 3.0.1 beta
Version 3.0.2 beta
Version 3.1.0 beta
Version 3.1.0 beta
Version 3.1.1 beta
Version 3.1.1 beta
Version 3.1.2 beta
Version 3.1.3 beta

Timeline

No history available yet.