CVE Database
/

CVE-2021-3632

Back to search

CVE-2021-3632

Published: Aug 26, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

VendorProductVersions

n/a

keycloak

affected
Fixed in v15.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now