NA

CVE-2021-3632

Published: 26/08/2022 Updated: 23/11/2022
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat single sign-on 7.0

redhat keycloak

redhat single_sign-on

Vendor Advisories

No description is available for this CVE ...
A security issue was found in keycloak where it possible for anyone to register a new security device/key when there is no device already registered for any user using WebAuthn password-less login flow ...