CyberSec.Space Logo
CVEブラウザに戻る

CVE-2021-46249

MEDIUM
6.5
CVSS Severity Score
EPSS Score0.1680%
EPSS Percentile40.12th
Published2022年2月15日
Last Modified2024年11月21日

Vulnerability Description

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.

Affected Platforms (CPE)

📦
Scratchoauth2 Project

Scratchoauth2

< 2021-04-12

References & Advisories

関連する脆弱性情報