OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal https://openvpn.net/vpn-server-resources/release-notes/#openvpn-access-server-2-11-0
Created openvpn tracking bugs for this issue: Affects: epel-all [bug 2120483] Affects: fedora-all [bug 2120484]
This is about OpenVPN ACCESS SERVER. That is not a Fedora package project. Removing myself from this ticket.
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.