Collected research
Real-life OIDC Security (II): Login Confusion
Describes Login Confusion: where a service provider honours a post-login redirect parameter and also exposes an unprotected login-initiation endpoint, the victim can be pushed into a silent OpenID Connect flow immediately after typing credentials, ending up logged in as their linked identity provider account instead. Shown on Bitbucket Server.
Record
- Researcher
- Lauritz Holtmann
- Published by
- (Web-)Insecurity Blog
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Lauritz Holtmann, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .