A vulnerability in the eap-peap and eap-ttls plugins related to the propagation of authentication details from inner EAP methods was discovered in strongSwan that can result in incorrect identity binding and potential authorization bypass. All versions since 4.5.0 are affected.