craftcms/cms is vulnerable to Authentication Bypass by Capture-replay
57
Medium Risk
Craft CMS accepts WebAuthn request options from the unauthenticated passkey-login request body and does not persist the updated credential counter after a successful assertion. A captured passkey-login request body can therefore be replayed because the old challenge is accepted again and the stored signature counter remains stale. Replaying one successful assertion body creates additional authenticated sessions for the victim account. The fix binds the assertion to a server-issued challenge and persists the updated credential counter.
You are affected if you are using a version that falls within the vulnerable range and you have passkey (WebAuthn) login enabled.
craftcms/cms is vulnerable to Authentication Bypass by Capture-replay in versions 5.0.0 - 5.10.4.1.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant