Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对函数返回值的检查不正确
Vulnerability Title
java-webauthn-server 安全漏洞
Vulnerability Description
java-webauthn-server是Yubico开源的一款Java服务端Web认证库。 java-webauthn-server 2.8.0版本至2.8.2之前版本存在安全漏洞,该漏洞源于在第二因素流程中错误检查函数返回值,可能导致身份冒充。
CVSS Information
N/A
Vulnerability Type
N/A