CVE-2021-46250

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/02/2022
Last modified:
24/02/2022

Description

An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:scratchoauth2_project:scratchoauth2:*:*:*:*:*:scratch:*:* 2021-04-13 (excluding)