CVE-2021-20230 describes a flaw in stunnel versions prior to 5.57, where improper client certificate validation occurs when both redirect and verifyChain options are enabled. This allows an attacker with a certificate from an unauthorized Certificate Authority to bypass redirection and access the tunneled service, primarily impacting confidentiality. With a CVSS score of 7.5 (High), this vulnerability is network-exploitable with low complexity, requiring no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.57CPE matchmatch criteria | cpe:2.3:a:stunnel:stunnel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in stunnel before 5.57 where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an attacker with a certificate signed by a Certificate Authority which is not the one accepted by the stunnel server to access the tunneled service instead of being redirected to the address specified in the redirect option. The highest threat from this vulnerability is to confidentiality.
Feb 9, 2021stunnel: client certificate not correctly verified when redirect and verifyChain options are used
Oct 11, 2020