Releases58
Frequency1 month 1 week
Last Release
Stars433
Experimental Single Sign On server, OAuth2, Openid Connect, multiple factor authentication with, HOTP/TOTP, FIDO2, TLS Certificates, etc. extensible via plugins

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.

9.8 CRITICAL

scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registration.

7.5 HIGH5 MEDIUM

static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.

9.8 CRITICAL7.5 HIGH

scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion.

8.8 HIGH6.5 MEDIUM

Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.

9.8 CRITICAL7.5 HIGH

scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webauthn registration.