VDB
Sign up
LOW3.1

GHSA-7g5x-9c4v-4w5r

Keycloak REST Services has a WebAuthn Attestation Statement Verification Bypass

Quick fix

GHSA-7g5x-9c4v-4w5r — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.4.4</version> for org.keycloak:keycloak-services

Details

A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is configured to require direct attestation. This can lead to weakened authentication integrity and unauthorized authenticator registration.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 26.4.4
Fix# pom.xml: bump <version>26.4.4</version> for org.keycloak:keycloak-services

References