Known Vulnerabilities for Scratchoauth2 by Scratchoauth2 Project
Listed below are 4 of the newest known vulnerabilities associated with "Scratchoauth2" by "Scratchoauth2 Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-46251 json | A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attacke... | 6.1 - MEDIUM | 2022-02-15 | 2022-02-24 |
| CVE-2021-46250 json | An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to ... | 10 - CRITICAL | 2022-02-15 | 2022-02-24 |
| CVE-2021-46249 json | An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b... | 6.5 - MEDIUM | 2022-02-15 | 2022-07-12 |
| CVE-2021-29437 json | ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a ... | 6.8 - MEDIUM | 2021-04-13 | 2023-06-26 |