Replies: 3 comments 9 replies
-
From the CWE-601 description:
In the case of an application with However, it seems possible to alter the It should be noted that:
So, nothing very special regarding
|
Beta Was this translation helpful? Give feedback.
-
I'm not too happy about this being in a public Github discussion already, but since the cat is out of the bag now: I can put a link like
somewhere. A user who follows that link will go through the legit application's OAuth2 flow, but then end up at the malicious application, which doesn't have to care about session or csrf token from the legit application at all. No front-end involved at all. |
Beta Was this translation helpful? Give feedback.
-
Closing in favor of: |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Beta Was this translation helpful? Give feedback.
All reactions