QID 376189

Date Published: 2021-12-21

QID 376189: Stunnel Improper Certificate Validation Vulnerability

Stunnel is an open-source multi-platform application used to provide a universal TLS/SSL tunneling service.

A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options.

Affected Version:
Version less than 5.57

This flaw allows an attacker with a certificate signed by a Certificate Authority, which is not the one accepted by the stunnel server, to access the tunneled service instead of being redirected to the address specified in the redirect option.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    For more information please visit Stunnel for updates and patch information.

    CVEs related to QID 376189

    Software Advisories
    Advisory ID Software Component Link
    stunnel URL Logo www.stunnel.org/downloads.html