4 ms·
CVE-2023-28131 was published in April. But yes, great question I think OpenId solves some of the issues, at least for authentication, not authorization.
by greenviad 3y ago
CVE-2023-28131 was published in April.
But yes, great question
I think OpenId solves some of the issues, at least for authentication, not authorization.
- aviCC 3y agoActually, the CVE-2023-283131 vulnerability was published with the full details just two days ago. In April Expo published a short post but without too much technical information. You can find more details about CVE-2023-283131 in the link I shared here: https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services https://salt.security/blog/a-new-oauth-vulnerability-that-ma.... Thank you for bringing up the distinction, and I agree that OpenID can help address some of the issues, but not all of them...
- stop50 3y agoCould SAML solve them in your eyes?