Vulnerabilities > Scratchoauth2 Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-02-15 | CVE-2021-46249 | Authorization Bypass Through User-Controlled Key vulnerability in Scratchoauth2 Project Scratchoauth2 An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps. | 6.5 |
2022-02-15 | CVE-2021-46250 | Unspecified vulnerability in Scratchoauth2 Project Scratchoauth2 An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2. | 10.0 |
2022-02-15 | CVE-2021-46251 | Cross-site Scripting vulnerability in Scratchoauth2 Project Scratchoauth2 A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. | 6.1 |
2021-04-13 | CVE-2021-29437 | Unspecified vulnerability in Scratchoauth2 Project Scratchoauth2 ScratchOAuth2 is an Oauth implementation for Scratch. | 6.8 |