Web Hack List

Collected research

Attacks via a New OAuth flow, Authorization Code Injection, and Whether HttpOnly, PKCE, and BFF Can Help

Attacks via a New OAuth flow, Authorization Code Injection, and Whether HttpOnly, PKCE, and BFF…

An attacker who can run script on any page of an OAuth client's origin starts a fresh authorization code flow in a hidden frame, breaks the flow so the application never consumes the code, and replays the stolen authorization response from their own machine. This yields an authenticated session even with a confidential client, a backend-for-frontend, PKCE, state and nonce.

Record

Document
Attacks via a New OAuth flow, Authorization Code Injection, and Whether HttpOnly, PKCE, and BFF…
Researcher
Andrey Kuznetsov
Published by
Medium
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Andrey Kuznetsov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .