CyberSec.Space Logo
Back to CVE Browser

CVE-2021-46249

MEDIUM
6.5
CVSS Severity Score
EPSS Score0.1680%
EPSS Percentile40.12th
PublishedFeb 15, 2022
Last ModifiedNov 21, 2024

Vulnerability Description

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.

Affected Platforms (CPE)

📦
Scratchoauth2 Project

Scratchoauth2

< 2021-04-12

References & Advisories

Related Vulnerabilities