OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15078
Reference (s):
- FEDORA:FEDORA-2021-242ef81244
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/GJUXEYHUPREEBPX23VPEKMFXUPVO3PMU/
- FEDORA:FEDORA-2021-b805c26afa
- URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/PLDB3OBQ3AODYYRN7NRCABV6I4AUFAT6/
- FEDORA:FEDORA-2021-d6b9d8497b

