Earlier quoted context omitted.
The vulnerability came from the outlook-integration.harvestapp.com. It used a JSON object as `state` containing instructions once the OAuth2 Callback succeeded. The property `subdomain` was used to redirect the browser to a subdomain of harvestapp.com, passing the `#id-token`. The problem came from the fact that the value of `subdomain` was injected directly to: https://${subdomain}.harvestapp.com/...#id-token= ... B…
So it was the combination of: * the additional redirect using the JSON object in state * the `subdomain` not being properly verified * the implicit grant being supported Which allowed an attacker to get an access token for a user's Microsoft account. From my reading, this seems to be entirely an issue due to an improper implementation on Harvest's side, nothing to do with Microsoft's implementation of OAuth. Am I cor…
I assume that for several years though, that was exactly what Microsoft thought too.