Логотип exploitDog
bind:CVE-2022-29222
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-29222

Количество 4

Количество 4

ubuntu логотип

CVE-2022-29222

больше 3 лет назад

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it doesn't posses the private key for and Pion DTLS wouldn't reject it. This issue affects users that are using Client certificates only. The connection itself is still secure. The Certificate provided by clients can't be trusted when using a Pion DTLS server prior to version 2.1.5. Users should upgrade to version 2.1.5 to receive a patch. There are currently no known workarounds.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-29222

больше 3 лет назад

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it doesn't posses the private key for and Pion DTLS wouldn't reject it. This issue affects users that are using Client certificates only. The connection itself is still secure. The Certificate provided by clients can't be trusted when using a Pion DTLS server prior to version 2.1.5. Users should upgrade to version 2.1.5 to receive a patch. There are currently no known workarounds.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2022-29222

больше 3 лет назад

Pion DTLS is a Go implementation of Datagram Transport Layer Security. ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-w45j-f832-hxvh

больше 3 лет назад

Pion/DLTS Accepts Client Certificates Without CertificateVerify

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-29222

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it doesn't posses the private key for and Pion DTLS wouldn't reject it. This issue affects users that are using Client certificates only. The connection itself is still secure. The Certificate provided by clients can't be trusted when using a Pion DTLS server prior to version 2.1.5. Users should upgrade to version 2.1.5 to receive a patch. There are currently no known workarounds.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-29222

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it doesn't posses the private key for and Pion DTLS wouldn't reject it. This issue affects users that are using Client certificates only. The connection itself is still secure. The Certificate provided by clients can't be trusted when using a Pion DTLS server prior to version 2.1.5. Users should upgrade to version 2.1.5 to receive a patch. There are currently no known workarounds.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-29222

Pion DTLS is a Go implementation of Datagram Transport Layer Security. ...

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w45j-f832-hxvh

Pion/DLTS Accepts Client Certificates Without CertificateVerify

CVSS3: 5.9
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу