CVE-2021-3632
26.08.2022, 16:15
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | keycloak | 𝑥 < 15.1.0 |
redhat | single_sign-on | 7.0 |
redhat | single_sign-on | 7.4 ≤ 𝑥 < 7.4.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References