Top 10 winner
Hijacking OAUTH flows via Cookie Tossing
Extends the little-documented cookie tossing technique, in which control of a subdomain permits setting cookies scoped to the parent domain with a narrow Path so they take precedence on chosen endpoints. Applied to a cloud development environment, tossing the attacker's session cookie onto the OAuth callback paths caused the victim's Git provider account to be linked to the attacker's account (CVE-2024-21583). SameSite offers no protection here; the __Host- cookie prefix does.
Record
- Researcher
- Elliot Ward
- Published by
- Snyk Labs
- Date
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Elliot Ward, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .