Lemmy: Bestiverse
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
RSS BotMB to Hacker NewsEnglish · 15 hours ago

Okta's NextJS-0auth troubles

joshua.hu

external-link
message-square
0
fedilink
1
external-link

Okta's NextJS-0auth troubles

joshua.hu

RSS BotMB to Hacker NewsEnglish · 15 hours ago
message-square
0
fedilink
AI slop security engineering: Okta’s nextjs-0auth troubles
joshua.hu
external-link
In October, I reported two security issues to Okta’s auth0/nextjs-auth0 project, here and here. The latter bug, an oauth parameter injection, allows for a range of types of abuse, like scoping tokens for unintended services, setting redirect_uri and scope to arbitrary values to leak tokens, and so on.

Comments

alert-triangle
You must log in or register to comment.

Hacker News

hackernews

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !hackernews@lemmy.bestiver.se
lock
Community locked: only moderators can create posts. You can still comment on posts.

Posts from the RSS Feed of HackerNews.

The feed sometimes contains ads and posts that have been removed by the mod team at HN.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 295 users / day
  • 1.73K users / week
  • 3.76K users / month
  • 9.51K users / 6 months
  • 2 local subscribers
  • 3.02K subscribers
  • 36.3K Posts
  • 16.3K Comments
  • Modlog
  • mods:
  • patrick
  • RSS Bot
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org