Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
ScratchOAuth2 安全漏洞
Vulnerability Description
Kenny2github ScratchOAuth2是Kenny2github开源的一个应用软件。验证Scratch帐户是否真实,以用于授权或识别。 ScratchOAuth2存在安全漏洞,该漏洞源于ScratchOAuth2的SOA2Login::comment中身份验证存在问题,允许攻击者可利用该漏洞在依赖于ScratchOAuth2的下游组件上作为其他用户进行身份验证。
CVSS Information
N/A
Vulnerability Type
N/A