Impact
The vulnerability arises because the backend relies on a client‑side configuration file to identify the user. When a user edits the UID field in the config.json before authenticating, the server accepts it without verifying that the OAuth2 token actually belongs to that UID. This flaw allows the attacker to assume any account, performing authorized actions on its behalf. The weakness is a classic authentication bypass (CWE‑287) coupled with lack of proper input validation (CWE‑602) and insecure handling of privileged tokens (CWE‑349).
Affected Systems
This issue affects LaciSynchroni server The affected component is the OAuth2 authentication endpoint located in the SecretKeyAuthenticatorService. Customers running the v1.2.1 and v1.2.2 builds, or any manual deployment using those source tags, are vulnerable.
Risk and Exploitability
The CVSS score of 9.2 places this flaw in the critical range. Due to the lack of a network‑access requirement, the EPSS score is not available, implying that the exploitation likelihood is not quantified in the public dataset. However, the attacker only needs local access to the client configuration file or the ability to modify it before the login process; no external network attack is described. Consequently, internal threat actors or compromised clients can exploit the flaw. The flaw is not currently listed in CISA's KEV catalog, but the high severity warrants immediate remediational action. The server now validates the OAuth2 identity against the requested UID, eliminating the impersonation path once updated to v1.2.3.
OpenCVE Enrichment