Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Webauthn-Framework 授权问题漏洞
Vulnerability Description
Webauthn-Framework是一个身份验证机制。用于 Web 应用程序创建和使用强大的、经过证明的、有范围的、基于公钥的凭证,以便对用户进行强身份验证。 Webauthn-Framework 存在安全漏洞,控制用户系统的攻击者能够使用附加的FIDO2身份验证器登录易受攻击的服务,而无需通过用户存在检查。
CVSS Information
N/A
Vulnerability Type
N/A