Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
1–10 of 114 posts
Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#2Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#3It took THREE YEARS (August 2020 - August 2023) to fix the vulnerability? I'm not sure the size of the Harvest team, but that still seems insane.
Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#4Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#5It took THREE YEARS (August 2020 - August 2023) to fix the vulnerability? I'm not sure the size of the Harvest team, but that still seems insane.
I'm guessing, as would be typical of many companies, it ended up on a backlog as low priority, survived a few Jira reorganisations and corporate restructuring, before eventually being noticed and fixed.
Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#6It took THREE YEARS (August 2020 - August 2023) to fix the vulnerability? I'm not sure the size of the Harvest team, but that still seems insane.
I'm guessing, as would be typical of many companies, it ended up on a backlog as low priority, survived a few Jira reorganisations and corporate restructuring, before eventually being noticed and fixed.
Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#7Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#8FYI, they are omitting it in the upcoming OAuth 2.1 spec: https://www.ietf.org/archive/id/draft-ietf-oauth-v2-1-09.htm...
Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#9Earlier quoted context omitted.
I'm guessing, as would be typical of many companies, it ended up on a backlog as low priority, survived a few Jira reorganisations and corporate restructuring, before eventually being noticed and fixed.
They're a small company with an even smaller engineering team, I think 13 devs or something like that. I would imagine either everyone knows about it immediately or they are too overloaded with work that it gets deprioritised into oblivion after a quick first look.
Re: Stealing OAuth tokens of Microsoft accounts via open redirect in Harvest App
#10Earlier quoted context omitted.
I'm guessing, as would be typical of many companies, it ended up on a backlog as low priority, survived a few Jira reorganisations and corporate restructuring, before eventually being noticed and fixed.
They're a small company with an even smaller engineering team, I think 13 devs or something like that. I would imagine either everyone knows about it immediately or they are too overloaded with work that it gets deprioritised into oblivion after a quick first look.