Title

Authentication bypass with the "redirect" option

Description

stunnel does not perform redirection when both "redirect" and "verifyChain" options are used, and a client authenticates with an untrusted certificate.

Exploitability

The vulnerability is exploitable under the following conditions:

Impact

This vulnerability bypasses authentication based on client certificates.

CVSS v2 Score

CVSS v2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N)

Recommendation

Upgrade to stunnel 5.57 or later.

As a workaround, remove the "redirect" option from the configuration file.

Credits

Timeline

Our supporters:
Go to the top