THREAT OPS › Threat News › [GHSA] GHSA-wg23-69c2-gjc8 (critical) — Craft CMS: Passkey login accepts replayed WebAuthn assertions
[GHSA] GHSA-wg23-69c2-gjc8 (critical) — Craft CMS: Passkey login accepts replayed WebAuthn assertions
GHSA-wg23-69c2-gjc8 Severity: critical CVE: None
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Craft CMS passkey login accepts WebAuthn requestOptions from the unauthenticated login request body and does not persist the updated credential counter returned by the WebAuthn assertion validator. A captured passkey login request body can therefore be replayed because the old challenge
Original source: https://github.com/advisories/GHSA-wg23-69c2-gjc8