PT-2019-1902 · Coturn · Coturn

Published

2019-01-28

·

Updated

2022-06-07

·

CVE-2018-4058

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions coTURN versions prior to 4.5.0.9
Description The issue is related to an unsafe default configuration in the coTURN server, which allows the relaying of external traffic to the loopback interface of its own host. This can provide access to other private services running on that host, potentially leading to further attacks. An attacker can exploit this by setting up a relay with a loopback address as the peer on an affected TURN server.
Recommendations For coTURN versions prior to 4.5.0.9, update to version 4.5.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the TURN server functionality to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01560
CVE-2018-4058
DLA-1671-1
DSA-4373-1

Affected Products

Coturn