Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.
{
"severity": "CRITICAL",
"cwe_ids": [
"CWE-863"
],
"nvd_published_at": "2021-09-27T06:15:00Z",
"github_reviewed_at": "2021-09-28T21:04:00Z",
"github_reviewed": true
}