Collected research
Covert Redirect Vulnerability Related to OAuth 2.0 and OpenID
OAuth 2.0 and OpenID Covert Redirect Vulnerability
OAuth 2.0 and OpenID providers accept loosely validated redirect targets pointing at domains a client has whitelisted but which carry open redirect or XSS flaws. Chaining the two makes the provider hand an access token or OpenID profile data to a site the attacker controls, affecting most major single sign-on providers.
Record
- Document
- OAuth 2.0 and OpenID Covert Redirect Vulnerability
- Researcher
- Wang Jing
- Published by
- tetraph.com
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Wang Jing, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .