Lucene search

K
osvGoogleOSV:GO-2021-0104
HistoryJul 28, 2021 - 6:08 p.m.

Authorization bypass in github.com/pion/webrtc/v3

2021-07-2818:08:05
Google
osv.dev
14

0.001 Low

EPSS

Percentile

38.8%

Due to improper error handling, DTLS connections were not killed when certificate verification failed, causing users who did not check the connection state to continue to use the connection. This could allow allow an attacker which holds the ICE password, but not a valid certificate, to bypass this restriction.

CPENameOperatorVersion
github.com/pion/webrtc/v3lt3.0.15

0.001 Low

EPSS

Percentile

38.8%

Related for OSV:GO-2021-0104