Top 10 winner
Hidden OAuth attack vectors
Three attacks on OAuth2 and OpenID Connect endpoints that a browser never reveals. Dynamic client registration accepts attacker URLs in logo_uri, jwks_uri and request_uris, giving second-order SSRF; keeping redirect_uri in the session lets a second request poison it and steal the code; and the WebFinger endpoint allows user enumeration and LDAP injection.
Record
- Researcher
- Michael Stepankin
- Published by
- PortSwigger Research
- Date
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Michael Stepankin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .