Abandoned reply URL in Azure AD app could let attackers gain privileges to launch attacks

An Azure Active Directory (AD) app with an abandoned reply URL address was recently observed, a situation that could let an attacker leverage the abandoned URL to redirect authorization codes to themselves, exchanging the fraudulently obtained authorization codes for access tokens. In a blog post Aug.

Source: SC Magazine

 


Date:

Categorie(s):