Unverified Ownership of Resource Affecting openvpn package, versions [,2.5.10) [2.6.0,2.6.10)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.07% (32nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-OPENVPN-7689943
- published 16 Aug 2024
- disclosed 8 Jul 2024
- credit Vladimir Tokarev
Introduced: 8 Jul 2024
CVE-2024-27903 Open this link in a new tabHow to fix?
Upgrade openvpn
to version 2.5.10, 2.6.10 or higher.
Overview
Affected versions of this package are vulnerable to Unverified Ownership of Resource due to the ability to load plug-ins from any directory. An attacker can manipulate the OpenVPN service by loading an arbitrary plug-in.
Note:
When chained with CVE-2024-27459, it could result in remote code execution.