{"id":"GHSA-6whf-q6p5-84wg","summary":"Improper Access Control in Webauthn Framework","details":"Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.","aliases":["CVE-2021-38299"],"modified":"2024-02-17T05:26:54.961182Z","published":"2021-09-29T17:16:07Z","database_specific":{"github_reviewed_at":"2021-09-28T21:04:00Z","nvd_published_at":"2021-09-27T06:15:00Z","cwe_ids":["CWE-863"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-38299"},{"type":"WEB","url":"https://github.com/web-auth/webauthn-framework/commit/572e239c5702667ca52487faf861abc768a46308"},{"type":"PACKAGE","url":"https://github.com/web-auth/webauthn-framework"},{"type":"WEB","url":"https://github.com/web-auth/webauthn-framework/releases"},{"type":"WEB","url":"https://github.com/web-auth/webauthn-framework/releases/tag/v3.3.4"},{"type":"WEB","url":"https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2021-1-fehlende-ueberpruefung-von-user-presence-in-webauthn-framework"}],"affected":[{"package":{"name":"web-auth/webauthn-framework","ecosystem":"Packagist","purl":"pkg:composer/web-auth/webauthn-framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"3.3.4"}]}],"versions":["v3.3.0","v3.3.1","v3.3.2","v3.3.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-6whf-q6p5-84wg/GHSA-6whf-q6p5-84wg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}