CVE-2020-25200: Information Exposure
(updated )
Pritunl allows attackers to enumerate valid VPN usernames via a series of /auth/session
login attempts. Initially, the server will return err However, if the username is valid, then login attempts, the server will start responding with err Invalid usernames will receive err indefinitely.
References
Detect and mitigate CVE-2020-25200 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →