CVE-2022-29222

MEDIUM

Pion DTLS <2.1.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.5, a DTLS Client could provide a Certificate that it doesn't posses the private key for and Pion DTLS wouldn't reject it. This issue affects users that are using Client certificates only. The connection itself is still secure. The Certificate provided by clients can't be trusted when using a Pion DTLS server prior to version 2.1.5. Users should upgrade to version 2.1.5 to receive a patch. There are currently no known workarounds.

References (3)

Core 3
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/pion/dtls/releases/tag/v2.1.5

Scores

CVSS v3 5.9
EPSS 0.0030
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (2)
pion/dtls < 2.1.5
pion/dtls 0 - 2.1.5 (2 CPE variants)Go
Published May 21, 2022
Tracked Since Feb 18, 2026