Security Advisory
CVE-2021-28681
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Pion WebRTC before 3.0.15 didnt properly tear down the DTLS Connection when certificate verification failed. The PeerConnectionState was set to failed, but a user could ignore that and continue to use the PeerConnection. )A WebRTC implementation shouldnt allow the user to continue if verification has failed.)