VDB
Sign up
MEDIUM5.3

GHSA-74xm-qj29-cq8p

In github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication

Quick fix

GHSA-74xm-qj29-cq8p — github.com/pion/webrtc/v3: upgrade to the fixed version with the command below.

go get github.com/pion/webrtc/v3@v3.0.15

Details

### Impact Data channel communication was incorrectly allowed with users who have failed DTLS certificate verification.

This attack requires * Attacker knows the ICE password. * Only take place during PeerConnection handshake.

This attack can be detected by monitoring `PeerConnectionState` in all versions of Pion WebRTC.

### Patches Users should upgrade to v3.0.15.

The exact patch is https://github.com/pion/webrtc/commit/545613dcdeb5dedb01cce94175f40bcbe045df2e

### Workarounds Users should listen for when `PeerConnectionState` changes to `PeerConnectionStateFailed`. When it enters this state users should not continue using the PeerConnection.

### For more information If you have any questions or comments about this advisory: * Open an issue in https://github.com/pion/webrtc * Email us at [team@pion.ly](mailto:team@pion.ly)

Thank you to https://github.com/Gaukas for discovering this.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/pion/webrtc/v3
Introduced in: 0Fixed in: 3.0.15
Fixgo get github.com/pion/webrtc/v3@v3.0.15

References