Lucene search

K
osvGoogleOSV:GO-2020-0038
HistoryApr 14, 2021 - 8:04 p.m.

Improper authentication in github.com/pion/dtls

2021-04-1420:04:52
Google
osv.dev
8
improper authentication
unencrypted data
data injection
github
software

AI Score

9.5

Confidence

High

EPSS

0.013

Percentile

86.0%

Due to improper verification of packets, unencrypted packets containing application data are accepted after the initial handshake. This allows an attacker to inject arbitrary data which the client/server believes was encrypted, despite not knowing the session key.

AI Score

9.5

Confidence

High

EPSS

0.013

Percentile

86.0%

Related for OSV:GO-2020-0038