Description
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6610 | A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow. |
Github GHSA |
GHSA-qpq9-jpv4-6gwr | Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flow |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:08.129Z
Reserved: 2021-07-01T00:00:00.000Z
Link: CVE-2021-3632
No data.
Status : Modified
Published: 2022-08-26T16:15:09.110
Modified: 2024-11-21T06:22:01.653
Link: CVE-2021-3632
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA