cookie-sharing

1 article
sort: new top best
clear filter
0 5/10

A subdomain takeover of ping.ubnt.com via unclaimed Amazon CloudFront distribution combined with shared session cookies across *.ubnt.com subdomains enabled complete authentication bypass of Ubiquity's SSO system. The vulnerability was responsibly disclosed via HackerOne.

Ubiquity ubnt.com ping.ubnt.com sso.ubnt.com Amazon Cloudfront HackerOne Arne Swinnen
arneswinnen.net · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details