Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g28r-w65r-h89m

Опубликовано: 19 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

EPSS

Процентиль: 63%
0.00452
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-305

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
nvd
больше 3 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVSS3: 9.8
debian
больше 3 лет назад

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass ...

suse-cvrf
около 3 лет назад

Security update for openvpn

suse-cvrf
около 3 лет назад

Security update for openvpn

EPSS

Процентиль: 63%
0.00452
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-305