Yubico/java-webauthn-server

Yubico/java-webauthn-server

Releases130
Frequency1 month 1 day
Last Release
Stars555
Server-side Web Authentication library for Java https://www.w3.org/TR/webauthn/#rp-operations

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.