VendorsScratchOAuth2 Projectscratchoauth2all versions
Vulnerabilities

ScratchOAuth2 Project ScratchOAuth2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-46250
An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2.
Published 2022-02-15 · Modified
10.0EPSS 0.011
CVE-2021-29437
Account compromise by man-in-the-middle attack
Published 2021-04-13 · Modified
8.0EPSS 0.008
CVE-2021-46249
An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.
Published 2022-02-15 · Modified
6.5EPSS 0.006
CVE-2021-46251
A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
Published 2022-02-15 · Modified
6.1EPSS 0.006