Web Hack List

Top 10 winner

Hijacking OAUTH flows via Cookie Tossing

Extends the little-documented cookie tossing technique, in which control of a subdomain permits setting cookies scoped to the parent domain with a narrow Path so they take precedence on chosen endpoints. Applied to a cloud development environment, tossing the attacker's session cookie onto the OAuth callback paths caused the victim's Git provider account to be linked to the attacker's account (CVE-2024-21583). SameSite offers no protection here; the __Host- cookie prefix does.

Record

Researcher
Elliot Ward
Published by
Snyk Labs
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Elliot Ward, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .