Scratchoauth2 Project maintains a specialized OAuth 2.0 implementation whose vulnerability profile centers on its single core product and recurs through access-control and input-handling weaknesses, including authorization bypass, cross-site scripting, and improper neutralization flaws characteristic of authentication and session-management code. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scratchoauth2 Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46250CRITICAL An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components th | Feb 15, 2022 | 10.0 | 32 | NO | NO |
CVE-2021-46249MEDIUM An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set | Feb 15, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-46251MEDIUM A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a craft | Feb 15, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-29437MEDIUM ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scra | Apr 13, 2021 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scratchoauth2 Project.
Media articles that mention a CVE ID that affects a product developed by Scratchoauth2 Project — matched by CVE ID, not by vendor name.