CVE-2023-7245

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/02/2024
Last modified:
02/04/2025

Description

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openvpn:connect:*:*:*:*:*:windows:*:* 3.2.0 (including) 3.4.4 (excluding)
cpe:2.3:a:openvpn:connect:*:*:*:*:*:macos:*:* 3.2.0 (including) 3.4.8 (excluding)
cpe:2.3:a:openvpn:connect:3.0.0:beta:*:*:*:macos:*:*
cpe:2.3:a:openvpn:connect:3.0.0:beta:*:*:*:windows:*:*
cpe:2.3:a:openvpn:connect:3.0.1:beta:*:*:*:macos:*:*
cpe:2.3:a:openvpn:connect:3.0.2:beta:*:*:*:macos:*:*
cpe:2.3:a:openvpn:connect:3.1.0:beta:*:*:*:macos:*:*
cpe:2.3:a:openvpn:connect:3.1.0:beta:*:*:*:windows:*:*
cpe:2.3:a:openvpn:connect:3.1.1:beta:*:*:*:macos:*:*
cpe:2.3:a:openvpn:connect:3.1.1:beta:*:*:*:windows:*:*
cpe:2.3:a:openvpn:connect:3.1.2:beta:*:*:*:windows:*:*
cpe:2.3:a:openvpn:connect:3.1.3:beta:*:*:*:windows:*:*