A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
2022-08-26T16:15:09.110
2024-11-21T06:22:01.653
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | keycloak | < 15.1.0 | Yes |
Application | redhat | single_sign-on | 7.0 | Yes |
Application | redhat | single_sign-on | < 7.4.9 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | No |
Operating System | redhat | enterprise_linux | 7.0 | No |
Operating System | redhat | enterprise_linux | 8.0 | No |