Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to failed, but a user could ignore that and continue to use the PeerConnection. )A WebRTC implementation shouldn't allow the user to continue if verification has failed.)
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-03-18T03:20:06

Updated: 2021-03-18T23:28:05

Reserved: 2021-03-18T00:00:00


Link: CVE-2021-28681

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-03-18T04:15:14.617

Modified: 2021-03-25T13:45:41.487


Link: CVE-2021-28681

JSON object: View

cve-icon Redhat Information

No data.

CWE