CVE-2021-3632

HIGH7.5EPSS 0.50%

Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flow

Published: 8/27/2022Modified: 11/8/2023

Description

A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

References (7)