漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Account compromise by man-in-the-middle attack
Vulnerability Description
ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scratch user visits 3rd party site. 2. 3rd party site asks user for Scratch username. 3. 3rd party site pretends to be user and gets login code from ScratchOAuth2. 4. 3rd party site gives code to user and instructs them to post it on their profile. 5. User posts code on their profile, not knowing it is a ScratchOAuth2 login code. 6. 3rd party site completes login with ScratchOAuth2. 7. 3rd party site has full access to anything the user could do if they directly logged in. See referenced GitHub security advisory for patch notes and workarounds.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
授权机制不正确
Vulnerability Title
Kenny2github ScratchOAuth2 安全漏洞
Vulnerability Description
Kenny2github ScratchOAuth2是Kenny2github开源的一个应用软件。验证Scratch帐户是否真实,以用于授权或识别。 ScratchOAuth2 存在安全漏洞,该漏洞源于任何用户可以访问和修改的与scratchoauth2相关的数据都可以由第三方读取和修改。
CVSS Information
N/A
Vulnerability Type
N/A