Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.2.9"
},
{
"introduced": "3.3.0"
},
{
"fixed": "3.3.4"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:spomky-labs:webauthn_framwork:*:*:*:*:*:*:*:*"
}