Vulnerability Description
scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webauthn registration.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Glewlwyd Sso Server Project | Glewlwyd Sso Server | <= 2.5.3 |
Related Weaknesses (CWE)
References
- https://bugs.debian.org/993867Issue TrackingMailing ListThird Party Advisory
- https://github.com/babelouest/glewlwyd/commit/0efd112bb62f566877750ad62ee828bff5PatchThird Party Advisory
- https://bugs.debian.org/993867Issue TrackingMailing ListThird Party Advisory
- https://github.com/babelouest/glewlwyd/commit/0efd112bb62f566877750ad62ee828bff5PatchThird Party Advisory
FAQ
What is CVE-2021-40818?
CVE-2021-40818 is a vulnerability with a CVSS score of 9.8 (CRITICAL). scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webauthn registration.
How severe is CVE-2021-40818?
CVE-2021-40818 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-40818?
Check the references section above for vendor advisories and patch information. Affected products include: Glewlwyd Sso Server Project Glewlwyd Sso Server.