Vulnerabilities > CVE-2021-46249 - Authorization Bypass Through User-Controlled Key vulnerability in Scratchoauth2 Project Scratchoauth2

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
scratchoauth2-project
CWE-639

Summary

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.

Vulnerable Configurations

Part Description Count
Application
Scratchoauth2_Project
1