Skip to content

Seurcity Concerns on the Schema Rule method #1097

Open
@adamwan-nexplore

Description

@adamwan-nexplore

Configuration

  • Version: 0.X.Y
  • Integration: (native(Java/Kotlin))
  • Identity provider: OpenID

Description

The hackers should be able to claim custom scheme used in the redirect_uri parameter such that they can intercept the authentication code/token in Andriod.

Here is the related article.
https://blog.ostorlab.co/one-scheme-to-rule-them-all.html

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions