Other nomination
Attacks via a New OAuth flow, Authorization Code Injection, and Whether HttpOnly, PKCE, and BFF Can Help
An attacker who can run script on any page of an OAuth client's origin starts a fresh authorization code flow in a hidden frame, breaks the flow so the application never consumes the code, and replays the stolen authorization response from their own machine. This yields an authenticated session even with a confidential client, a backend-for-frontend, PKCE, state and nonce.
Record
- Researcher
- Andrey Kuznetsov
- Published by
- Medium
- Date
In the archive
Related sources
- Talk discussed and critiqued
- Earlier OAuth attack presentation
- OAuth demonstration application
- Russian version
Tags
This page is the archive's own catalogue record. The research is the work of Andrey Kuznetsov, first published at the original source. Preserved copies are kept so the citation survives its host.