Microsoft Account's OAuth tokens leaking via open redirect in Harvest App

https://eval.blog/research/microsoft-account-token-leaks-in-harvest/

Microsoft Account's OAuth tokens leaking via open redirect in Harvest App::Reported an OAuth token leak via open redirect in Harvest.

15 points · 5 comments · view on lemmy.world

5 Comments

ShunkW@lemmy.world · 2 pts · 2y

3 years from report to patch is fucking abysmal.

Knusper@feddit.de · 1 pts · 2y (3 replies)

Wow, I thought this was further reporting on their leaks earlier this year. Nono, it's another vulnerability. Microsoft really living up to their reputation...

jlar@lemmy.world · 2 pts · 2y (2 replies)

From the post: "I apologise for the poor and confusing title used before. I have updated the title but I cannot change it everywhere else. Just to clarify This is not a vulnerability in Microsoft.'

jlar@lemmy.world · 2 pts · 2y (1 reply)

Not to defend M$ lol. Just in this case it was Harvest with the vuln.

Knusper@feddit.de · 2 pts · 2y

Ah, thanks for the correction.