oauth-flow

1 article
sort: new top best
clear filter
0 8/10

A combination of login CSRF and HTTP Referer header-based open redirect in Airbnb's OAuth flow allowed attackers to steal OAuth access tokens from identity providers (Facebook/Google) and achieve authentication bypass on both web and mobile applications. The attack exploited the fact that Airbnb's /oauth_callback endpoint used the unvalidated HTTP Referer header for post-login redirection, combined with the ability to request access tokens via URL fragments instead of parameters.

Airbnb Arne Swinnen Facebook Google Slack Frans Rosén
arneswinnen.net · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details