The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password
The product assigns an owner to a resource, but the owner is outside of the intended control sphere.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://openvpn.net/vpn-server-resources/release-notes/ | release notes vendor advisory |