Web Hack List

Top 10 winner

Hidden OAuth attack vectors

Three attacks on OAuth2 and OpenID Connect endpoints that a browser never reveals. Dynamic client registration accepts attacker URLs in logo_uri, jwks_uri and request_uris, giving second-order SSRF; keeping redirect_uri in the session lets a second request poison it and steal the code; and the WebFinger endpoint allows user enumeration and LDAP injection.

Record

Researcher
Michael Stepankin
Published by
PortSwigger Research
Date
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Michael Stepankin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .