CVE-2021-28681Medium· 5.3▾ SunlitIn github.com/pion/webrtc, failed DTLS certificate verification doesn't stop data channel communication
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
Data channel communication was incorrectly allowed with users who have failed DTLS certificate verification.
This attack requires
This attack can be detected by monitoring PeerConnectionState in all versions of Pion WebRTC.
Users should upgrade to v3.0.15.
The exact patch is https://github.com/pion/webrtc/commit/545613dcdeb5dedb01cce94175f40bcbe045df2e
Users should listen for when PeerConnectionState changes to PeerConnectionStateFailed. When it enters this state users should not continue using the PeerConnection.
If you have any questions or comments about this advisory:
Thank you to https://github.com/Gaukas for discovering this.
github.com/pion/webrtc/v3 < 3.0.15Upgrade to a patched release:
github.com/pion/webrtc/v3 3.0.15Connected by shared product, vendor, weakness, or advisory.