Junglewise Threat Intelligence

CVE-2024-39912: The FIDO2/Webauthn Support for PHP library allows enumeration of valid usernames

CVE-2024-39912 · Severity: low · CVSS 3.1 · Published 2024-07-15

Technologies: web-auth/webauthn-framework (Packagist), web-auth/webauthn-lib (Packagist). Vendors: Packagist.

Executive brief

The FIDO2/Webauthn Support for PHP library allows enumeration of valid usernames

Affected products

  • Packagist web-auth/webauthn-framework
  • Packagist web-auth/webauthn-lib

Related threats