all InfoSec news
nOAuth
June 20, 2023, midnight |
The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org
authentication method on a web app. If an application relies on email attribute claims for authentication (which is
against best practice) and also merges user accounts without proper validation, an attacker could falsify an email
claim to gain full control over the target account. Descope and Microsoft Microsoft identified several popular multi-tenant
applications with users that used an email address with …
accounts app application authentication azure azure ad best practice claim claims control email log microsoft misconfiguration noauth practice validation web web app
More from www.cloudvulndb.org / The Open Cloud Vulnerability & Security Issue Database
AWS Amplify IAM role publicly assumable exposure
1 month, 2 weeks ago |
www.cloudvulndb.org
AWS Glue database password leakage
1 month, 3 weeks ago |
www.cloudvulndb.org
Synapse Analytics privilege escalation via intelligent caching
2 months, 3 weeks ago |
www.cloudvulndb.org
Azure Site Recovery privilege escalation
3 months, 2 weeks ago |
www.cloudvulndb.org
Azure HDInsight privilege escalation and DoS vulnerabilities
3 months, 3 weeks ago |
www.cloudvulndb.org
Jobs in InfoSec / Cybersecurity
CyberSOC Technical Lead
@ Integrity360 | Sandyford, Dublin, Ireland
Cyber Security Strategy Consultant
@ Capco | New York City
Cyber Security Senior Consultant
@ Capco | Chicago, IL
Sr. Product Manager
@ MixMode | Remote, US
Corporate Intern - Information Security (Year Round)
@ Associated Bank | US WI Remote
Senior Offensive Security Engineer
@ CoStar Group | US-DC Washington, DC