Blog | G5 Cyber Security

A research team has found two flaws in the OAuth 2.0 protocol

The OAuth 2.0 authentication protocol is widely used on social networking sites, every day billion of users access their profiles on Facebook and Google+ using it. According to researchers Daniel Fett, Ralf Ksters and Guido Schmitz from the University of Trier, the protocol is affected by a couple of vulnerabilities that could be exploited by attackers to subvert single sign-on authentication. In the first attack, IdPs inadvertently forward user credentials (ie, username and password) to the relying party (RP) or the attacker, in the second scenario the attacker can impersonate the victim.”]

Source: https://securityaffairs.co/wordpress/43518/digital-id/oauth-2-vulnerability.html

Exit mobile version