Skip to main content

Vendor/product archive

scratchoauth2_project / scratchoauth2 CVEs

Beta · best-effort

4 CVEs tagged to scratchoauth2_project / scratchoauth21 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2021-46251

Published Feb 15, 2022

A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a craf…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46250

Published Feb 15, 2022

An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-46249

Published Feb 15, 2022

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29437

Published Apr 13, 2021

ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scr…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1