CVE-2021-38299
27.09.2021, 06:15
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.Enginsight
Vendor | Product | Version |
---|---|---|
spomky-labs | webauthn_framwork | 𝑥 < 3.2.9 |
spomky-labs | webauthn_framwork | 3.3.0 ≤ 𝑥 < 3.3.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References