Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Keycloak: org.keycloak.authentication: keycloak: unauthorized account takeover via webauthn token replay
Vulnerability Description
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim's account. This leads to unauthorized enrollment of a hardware-backed credential, enabling persistent account takeover.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
N/A
Vulnerability Title
Keycloak 安全漏洞
Vulnerability Description
Keycloak是Keycloak开源的一种开源身份和访问管理解决方案。 Keycloak存在安全漏洞,该漏洞源于WebAuthn流程中的身份验证漏洞,允许远程攻击者重放ExecuteActionsActionToken令牌,可能导致攻击者注册自己的验证器到受害者账户,实现账户接管。
CVSS Information
N/A
Vulnerability Type
N/A