Web Hack List

Other nomination

Attacks via a New OAuth flow, Authorization Code Injection, and Whether HttpOnly, PKCE, and BFF Can Help

An attacker who can run script on any page of an OAuth client's origin starts a fresh authorization code flow in a hidden frame, breaks the flow so the application never consumes the code, and replays the stolen authorization response from their own machine. This yields an authenticated session even with a confidential client, a backend-for-frontend, PKCE, state and nonce.

Record

Researcher
Andrey Kuznetsov
Published by
Medium
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Andrey Kuznetsov, first published at the original source. Preserved copies are kept so the citation survives its host.