Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Progress Report on Handling an Actionable Security Vulnerability

Дата публикации: 29-05-2026 13:20:55

I gave a presentation at the 2026 OAuth Security Workshop in Leipzig describing the actions we took when an actionable security vulnerability was discovered affecting numerous OpenID and OAuth specifications. Much of the information discussed was not previously public. As I described when writing about a spec we created to address the problems, the security […]

Основное содержимое страницы с новостью.

OAuth Security WorkshopI gave a presentation at the 2026 OAuth Security Workshop in Leipzig describing the actions we took when an actionable security vulnerability was discovered affecting numerous OpenID and OAuth specifications. Much of the information discussed was not previously public.

As I described when writing about a spec we created to address the problems, the security vulnerability was identified during formal analysis of the OpenID Federation specification. The vulnerability resulted from ambiguities in the treatment of the audience values of tokens intended for the authorization server. The ambiguities enabled a malicious authorization server to use the token endpoint of a legitimate authorization server as the audience value, resulting in a client authentication JWT that the attacker could use there.

The presentation detailed how the vulnerability was discussed privately among authors of affected specifications, privately disclosed to affected parties and developers, disclosed to the OAuth working group, disclosed publicly by the OpenID Foundation, and fixed in the affected specifications (which is still a work in progress). I presented the tradeoffs considered, the decisions made and the reasons for them, and reflected on lessons learned. See the presentation deck I used (pptx) (pdf).

The thoughtful, careful, and timely action by those responsible for the affected specifications and ecosystems was impressive. I was honored to be part of it.

I’ll close by saying noting that the OAuth Security Workshop came into existence in November 2015 in response to an earlier security vulnerability also discovered through formal analysis. Describing our handling of another such vulnerability at this OSW was therefore certainly in keeping with the reasons for the workshop in the first place!

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1 Comment on Updates to Audience Values for OAuth 2.0 Authorization Servers by Progress Report on Handling an Actionable Security Vulnerability – Mike Jones: self-issued 015.3129-05-2026
2Presentation on the OpenID Federation Journey at TDI 2026011.8727-04-2026
3OpenID Presentations at April 2026 OpenID Workshop and IIW010.4128-04-2026
4Post-Quantum Presentation at TDI 2026014.8227-04-2026
5Carrot disclosure: Forgejo09.3528-04-2026
6GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability 06.9719-08-2026
7FlashME! – WordPress vulnerability disclosure [CVE-2016-9263]09.7719-10-2017
8AuthZEN at Identiverse 2026: authorization in the agent era0514-07-2026
9Oracle Security Alert for CVE-2026-21992 - 19 March 2026 032.2220-03-2026
10Атакована недоисправленная уязвимость в Windows-2609-07-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.97. Источник: self-issued.info.