Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2025-12150

10 месяцев назад

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-12150

6 месяцев назад

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-12150

6 месяцев назад

A flaw was found in Keycloak\u2019s WebAuthn registration component. T ...

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-7g5x-9c4v-4w5r

6 месяцев назад

Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-12150

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.

CVSS3: 3.1
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-12150

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.

CVSS3: 3.1
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-12150

A flaw was found in Keycloak\u2019s WebAuthn registration component. T ...

CVSS3: 3.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-7g5x-9c4v-4w5r

Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass

CVSS3: 3.1
0%
Низкий
6 месяцев назад

Уязвимостей на страницу