Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-09-27T05:55:51

Updated: 2024-08-04T01:37:16.357Z

Reserved: 2021-08-09T00:00:00

Link: CVE-2021-38299

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-27T06:15:07.910

Modified: 2022-07-12T17:42:04.277

Link: CVE-2021-38299

cve-icon Redhat

No data.