Executive brief
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
Affected products
- PyPI openvpn-monitor
Junglewise Threat Intelligence
CVE-2021-31605 · Severity: low · CVSS 3.1 · Published 2021-09-27
Technologies: openvpn-monitor (PyPI). Vendors: PyPI.
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.