CVE-2021-3632

HIGH7.5EPSS 0.50%

Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flow

發布日:2022/8/27修改日:2023/11/8

描述

A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

參考連結(7)