Scratchoauth2
Vendor:
First CVE: Apr 13, 2021 · Active for 5 years
4
Total CVEs
More Total CVEs than 72% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Scratchoauth2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2021
5 years ago
Most Recent CVE
Feb 15, 2022
1,623 days ago
CVE Severity & Scoring
Scratchoauth24 CVEs
75%
25%
All CVEs352,785 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High1 (25.0%)
Unknown0 (0.0%)
User Interaction
None2 (50.0%)
Unknown0 (0.0%)
Required2 (50.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None3 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46250CRITICAL An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components th | Feb 15, 2022 | 10.0 | 32 | NO | NO |
CVE-2021-46249MEDIUM An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set | Feb 15, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-46251MEDIUM A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows attackers to execute arbitrary web scripts or HTML via a craft | Feb 15, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-29437MEDIUM ScratchOAuth2 is an Oauth implementation for Scratch. Any ScratchOAuth2-related data normally accessible and modifiable by a user can be read and modified by a third party. 1. Scra | Apr 13, 2021 | 6.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Scratchoauth2
Top CWEs
Versions
No cataloged versions.