← Back to browse · API

CVE-2021-46250

Severity
CRITICAL
CVSS
10.0
EPSS
0.01052
Risk score
40.37
CISA KEV
No
PoC
No
Published
2022-02-15
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2021-32950, GHSA-JQRV-FV72-XJH3
Products
n/a:n/a n/a
Sources
euvd EUVD-2021-32950

Description

An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2.

References