Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v85q-g5fq-684c

Опубликовано: 17 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856dc704b2504cd3b92cf089fdd366dd40775d6 allows app owners to set flags that indicate whether an app is verified on their own apps.

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287