Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does n…
高危 CVSS 7.1
摘要
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by …
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/coturn/coturn/commit/37df0513168f830a7c9ce0a411db0300fa182f05
- https://github.com/coturn/coturn/security/advisories/GHSA-69wx-x7x6-pjj8
- https://github.com/coturn/coturn/security/advisories/GHSA-69wx-x7x6-pjj8
时间线
- nvd_ingest NVD