Back to search
CVE-2021-3632
Published: Aug 26, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
| Vendor | Product | Versions |
|---|---|---|
n/a | keycloak | affected Fixed in v15.1.0 |
Weaknesses (CWE)
References
https://issues.redhat.com/browse/KEYCLOAK-18500
x_refsource_MISC
https://bugzilla.redhat.com/show_bug.cgi?id=1978196
x_refsource_MISC
https://access.redhat.com/security/cve/CVE-2021-3632
x_refsource_MISC
https://github.com/keycloak/keycloak/pull/8203
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now