GHSA-74xm-qj29-cq8p
In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication
Quick fix
GHSA-74xm-qj29-cq8p — github.com/pion/webrtc/v3: upgrade to the fixed version with the command below.
go get github.com/pion/webrtc/v3@v3.0.15Details
### Impact Data channel communication was incorrectly allowed with users who have failed DTLS certificate verification.
This attack requires * Attacker knows the ICE password. * Only take place during PeerConnection handshake.
This attack can be detected by monitoring `PeerConnectionState` in all versions of Pion WebRTC.
### Patches Users should upgrade to v3.0.15.
The exact patch is https://github.com/pion/webrtc/commit/545613dcdeb5dedb01cce94175f40bcbe045df2e
### Workarounds Users should listen for when `PeerConnectionState` changes to `PeerConnectionStateFailed`. When it enters this state users should not continue using the PeerConnection.
### For more information If you have any questions or comments about this advisory: * Open an issue in https://github.com/pion/webrtc * Email us at [team@pion.ly](mailto:team@pion.ly)
Thank you to https://github.com/Gaukas for discovering this.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 3.0.15go get github.com/pion/webrtc/v3@v3.0.15References
- https://github.com/pion/webrtc/security/advisories/GHSA-74xm-qj29-cq8p[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-28681[ADVISORY]
- https://github.com/pion/webrtc/issues/1708[WEB]
- https://github.com/pion/webrtc/pull/1709[WEB]
- https://github.com/pion/webrtc/commit/545613dcdeb5dedb01cce94175f40bcbe045df2e[WEB]
- https://github.com/pion/webrtc[PACKAGE]
- https://pkg.go.dev/vuln/GO-2021-0104[WEB]