Blame

9dd048 Samuli Seppänen 2025-02-27 10:03:55 1
# CVE-2022-0547: Potential authentication by-pass with multiple deferred authentication plug-ins
c4f02d Samuli Seppänen 2025-01-29 08:37:37 2
9dd048 Samuli Seppänen 2025-02-27 10:03:55 3
OpenVPN 2.1 up to v2.4.11 and v2.5.5 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
9dd048 Samuli Seppänen 2025-02-27 10:03:55 5
This issue is resolved in OpenVPN 2.4.12 and v2.5.6 where the OpenVPN server process will stop running with the following error message in the logs:
c4f02d Samuli Seppänen 2025-01-29 08:37:37 6
7
```
9dd048 Samuli Seppänen 2025-02-27 10:03:55 8
Exiting due to multiple authentication plug-ins performing deferred authentication. Only one authentication plug-in doing deferred auth is allowed. Ignoring the result and stopping now, the current authentication result is not to be trusted.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 9
```
10
782f35 novaflash 2025-07-02 16:24:00 11
MITRE entry: https://www.cve.org/CVERecord?id=CVE-2022-0547