CVE-2021-38299

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
27/09/2021
Last modified:
12/07/2022

Description

Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:spomky-labs:webauthn_framwork:*:*:*:*:*:*:*:* 3.2.9 (excluding)
cpe:2.3:a:spomky-labs:webauthn_framwork:*:*:*:*:*:*:*:* 3.3.0 (including) 3.3.4 (excluding)