Collected research
OAuth 2.0 Redirect URI Validation Falls Short, Literally
The OAuth 2.0 rule to compare redirect_uri by simple string comparison guards only the domain, so appended path-confusion payloads and injected duplicate code parameters still pass validation, at 6 and 10 of 16 major identity providers respectively. Chained with an open redirect or an ad script anywhere on the client site, this leaks the victim's authorization code and yields account takeover.
Record
- Researcher
- Tommaso Innocenti, Matteo Golinelli, Kaan Onarlioglu, Ali Mirheidari, Bruno Crispo and Engin Kirda
- Published by
- ACSAC '23
- Format
- Whitepaper
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Tommaso Innocenti, Matteo Golinelli, Kaan Onarlioglu, Ali Mirheidari, Bruno Crispo and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .